Latest CVE Feed
-
5.4
MEDIUMCVE-2025-54682
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets allows Cross Site Request Forgery. This issue affects Connector for Gravity Forms and Google Sheets: from n/a through 1.2.4.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-54706
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Posts Display allows DOM-Based XSS. This issue affects Magical Posts Display: from n/a through 1.2.52.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-54690
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek Xinterio allows PHP Local File Inclusion. This issue affects Xinterio: from n/a through 4.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Path Traversal
-
9.3
CRITICALCVE-2025-54669
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RomanCode MapSVG allows SQL Injection. This issue affects MapSVG: from n/a through n/a.... Read more
Affected Products : mapsvg- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-54676
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita allows Stored XSS. This issue affects Online Booking & Scheduling Calendar for WordPres... Read more
Affected Products : online_booking_\&_scheduling_calendar_for_wordpress_by_vcita- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2025-54681
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets allows Phishing. This issue affects Connector for Gravity Forms and Google Sheets: from n/a through 1.2.4.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Misconfiguration
-
5.9
MEDIUMCVE-2025-54684
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Integration for Contact Form 7 and Constant Contact allows Stored XSS. This issue affects Integration for Contact Form 7 and Constant Contact: ... Read more
- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-54700
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Makeaholic allows PHP Local File Inclusion. This issue affects Makeaholic: from n/a through 1.8.4.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-52728
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel WordPress Plugin allows PHP Local File Inclusion. This issue affects Responsive Posts Carouse... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Path Traversal
-
4.2
MEDIUMCVE-2025-52712
Path Traversal vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Path Traversal. This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.8.... Read more
Affected Products : post_and_page_builder_by_boldgrid_-_visual_drag_and_drop_editor- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-52775
Missing Authorization vulnerability in Ronik@UnlimitedWP Project Cost Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Project Cost Calculator: from n/a through 1.0.0.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-49267
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps allows Blind SQL Injection. This issue affects Frontend Admin by DynamiApps: from n/a through 3.28.3.... Read more
Affected Products : frontend_admin- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-49062
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cornfeed WP-jScrollPane allows Reflected XSS. This issue affects WP-jScrollPane: from n/a through 2.0.3.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2025-49033
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows Blind SQL Injection. This issue affects ProfileGrid : from n/a through 5.9.5.3.... Read more
Affected Products : profilegrid- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-49054
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mrdenny Time Sheets allows Reflected XSS. This issue affects Time Sheets: from n/a through 2.1.3.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-49065
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BestiaDurmiente Visit Counter allows Stored XSS. This issue affects Visit Counter: from n/a through 1.0.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-49037
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Federico Rota Authentication and xmlrpc log writer allows Reflected XSS. This issue affects Authentication and xmlrpc log writer: from n/a through 1.2.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-47689
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in johnh10 Video Blogster Lite allows Reflected XSS. This issue affects Video Blogster Lite: from n/a through 1.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-54705
Missing Authorization vulnerability in magepeopleteam WpEvently allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpEvently: from n/a through 4.4.6.... Read more
Affected Products : event_manager_and_tickets_selling_for_woocommerce- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-24775
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms allows Upload a Web Shell to a Web Server. This issue affects Forms: from n/a through 2.9.0.... Read more
Affected Products : forms- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Misconfiguration