Latest CVE Feed
-
6.3
MEDIUMCVE-2025-8927
A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulation of the argument email leads to improper restriction o... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
-
10.0
CRITICALCVE-2025-25174
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 BeeTeam368 Extensions allows PHP Local File Inclusion. This issue affects BeeTeam368 Extensions: from n/a through 1.9.4.... Read more
Affected Products : vidmov- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.4
MEDIUMCVE-2025-28987
Server-Side Request Forgery (SSRF) vulnerability in PressForward PressForward allows Server Side Request Forgery. This issue affects PressForward: from n/a through 5.9.1.... Read more
Affected Products : pressforward- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-28999
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt WooCommerce Shop Page Builder allows Reflected XSS. This issue affects WooCommerce Shop Page Builder: from n/a through 2.27.7.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
8.1
HIGHCVE-2025-30635
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeAtelier IDonatePro allows PHP Local File Inclusion. This issue affects IDonatePro: from n/a through 2.1.9.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-30993
Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thank You Page Customizer for WooCommerce – Incre... Read more
Affected Products : woocommerce_thank_you_page_customizer- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-31007
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alvind Billplz Addon for Contact Form 7 allows Reflected XSS. This issue affects Billplz Addon for Contact Form 7: from n/a through 1.2.0.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-39483
Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer allows Code Injection. This issue affects Eventer: from n/a through 3.9.6.... Read more
Affected Products : eventer- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-47610
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wetail WooCommerce Fortnox Integration allows Stored XSS. This issue affects WooCommerce Fortnox Integration: from n/a through 4.5.6.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-47689
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in johnh10 Video Blogster Lite allows Reflected XSS. This issue affects Video Blogster Lite: from n/a through 1.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-48332
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks allows PHP Local File Inclusion. This issue affects Gutenberg Blocks: from n/a through 3.3.1.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
8.1
HIGHCVE-2025-49036
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addons for KingComposer allows PHP Local File Inclusion. This issue affects Premium Addons for KingComposer: ... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-49037
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Federico Rota Authentication and xmlrpc log writer allows Reflected XSS. This issue affects Authentication and xmlrpc log writer: from n/a through 1.2.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-49433
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThanhD Supermalink allows DOM-Based XSS. This issue affects Supermalink: from n/a through 1.1.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
8.8
HIGHCVE-2025-49869
Deserialization of Untrusted Data vulnerability in Arraytics Eventin allows Object Injection. This issue affects Eventin: from n/a through 4.0.31.... Read more
Affected Products : eventin- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-50031
Missing Authorization vulnerability in syedamirhussain91 DB Backup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DB Backup: from n/a through 6.0.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-50040
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moshensky CF7 Spreadsheets allows Stored XSS. This issue affects CF7 Spreadsheets: from n/a through 2.3.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
9.3
CRITICALCVE-2025-52720
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection. This issue affects Super Store Finder: from n/a through 7.5.... Read more
Affected Products : super_store_finder- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
8.8
HIGHCVE-2025-52732
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 Google Map Targeting allows PHP Local File Inclusion. This issue affects Google Map Targeting: from n/a through 1.1.6.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-54687
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs allows DOM-Based XSS. This issue affects JetTabs: from n/a through 2.2.9.1.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025