Latest CVE Feed
-
4.3
MEDIUMCVE-2025-5816
The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.0 via the get_order_detail() due to missing validation on a user con... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
7.6
HIGHCVE-2025-6023
An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fix... Read more
Affected Products : grafana- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-6233
Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.... Read more
Affected Products : mattermost_server- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
4.4
MEDIUMCVE-2025-6719
The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at... Read more
Affected Products : terms_descriptions- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-6813
The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible for authenticated attackers, with Subscriber-level access... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-7648
The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_button' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied ... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-7397
A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interface (CLI) in plain text within the command history. A local authenticated user that can access sensitive information like passwords wi... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-7444
The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthent... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-7785
A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the function sso of the file src/main/java/com/jeesite/modules/sys/web/SsoController.java. The manipulation of the argument redirect leads to ... Read more
Affected Products : jeesite- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-7797
A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. The manipulation of the argument base_init_url leads to null poi... Read more
Affected Products : gpac- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Denial of Service
-
6.3
MEDIUMCVE-2025-7789
A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The man... Read more
Affected Products : xxl-job- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-3740
The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access a... Read more
Affected Products : school_management_system- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
6.4
MEDIUMCVE-2025-5800
The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-6391
Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Information Disclosure
-
8.6
HIGHCVE-2025-7398
Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and 8036.... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cryptography
-
5.3
MEDIUMCVE-2025-7763
A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the function select of the file src/main/java/com/jeesite/modules/cms/web/SiteController.java of the component Site Controller. The manipulation ... Read more
Affected Products : jeesite- Published: Jul. 17, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-6053
The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the 'zuppler-online-ordering-options' page. This makes it pos... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.9
MEDIUMCVE-2025-7638
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user suppl... Read more
Affected Products : forminator- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-7660
The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attr... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-5811
The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Init() function in all versions up to, and including, 2.7. This makes it possible for unauthenticated atta... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization