Latest CVE Feed
-
4.9
MEDIUMCVE-2025-3295
The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected s... Read more
Affected Products : wp_editor- Published: Apr. 17, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
7.2
HIGHCVE-2025-3294
The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to ... Read more
Affected Products : wp_editor- Published: Apr. 17, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Path Traversal
-
9.9
CRITICALCVE-2024-3025
mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit this vulnerability by manipulating the logo filename to reference files outs... Read more
Affected Products : anythingllm- Published: Apr. 10, 2024
- Modified: Jul. 09, 2025
-
7.2
HIGHCVE-2024-3101
In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. By sending a specially crafted curl request with the 'multi_user_mode' parameter set to false, an attacker... Read more
Affected Products : anythingllm- Published: Apr. 10, 2024
- Modified: Jul. 09, 2025
-
7.2
HIGHCVE-2024-3283
A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment issue. The '/admin/system-preferences' API endpoint improperly authorizes manager-level users to modify the... Read more
Affected Products : anythingllm- Published: Apr. 10, 2024
- Modified: Jul. 09, 2025
-
7.5
HIGHCVE-2024-3569
A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a password. An attacker can exploit this vulnerability by making a request to the endpoint using the [valida... Read more
Affected Products : anythingllm- Published: Apr. 10, 2024
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2024-3570
A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers to execute arbitrary JavaScript in the context of a user's session. By manipulating the ChatBot responses, ... Read more
Affected Products : anythingllm- Published: Apr. 10, 2024
- Modified: Jul. 09, 2025
-
9.1
CRITICALCVE-2024-0404
A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unauthorized creation of high-privileged accounts. By intercepting and modifying the HTTP request during the account creation... Read more
Affected Products : anythingllm- Published: Apr. 16, 2024
- Modified: Jul. 09, 2025
-
8.1
HIGHCVE-2024-0549
mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, including critical database files such as 'anythingllm.db'. The vu... Read more
Affected Products : anythingllm- Published: Apr. 16, 2024
- Modified: Jul. 09, 2025
-
7.2
HIGHCVE-2024-3028
mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipulating the 'logo_filename' parameter in the 'system-preferences' API endpoint, an attacker can construct r... Read more
Affected Products : anythingllm- Published: Apr. 16, 2024
- Modified: Jul. 09, 2025
-
9.0
CRITICALCVE-2024-3029
In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-user' endpoint. This triggers an error that is caught by a catch block, which in turn deletes all users and d... Read more
Affected Products : anythingllm- Published: Apr. 16, 2024
- Modified: Jul. 09, 2025
-
6.5
MEDIUMCVE-2024-2913
A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invite, al... Read more
Affected Products : anythingllm- Published: May. 07, 2024
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-25461
A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a malicious XSS payload into the category name field. When a document is subsequently associated with this cate... Read more
Affected Products : seeddms- Published: Feb. 28, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-25477
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.... Read more
Affected Products : syspass- Published: Feb. 28, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-25476
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.... Read more
Affected Products : syspass- Published: Feb. 28, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-25478
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.... Read more
Affected Products : syspass- Published: Feb. 28, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-3880
The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on several functions in all versions up to, and including, 19.9.0. This makes it possible... Read more
Affected Products : poll\,_survey_\&_quiz_maker- Published: Jun. 17, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-5337
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This ... Read more
Affected Products : slider\,_gallery\,_and_carousel- Published: Jun. 14, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-5289
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ and 'mode' parameters in all versions up to, and including, 1.16.15 due to insufficient input san... Read more
Affected Products : 3d_flipbook- Published: Jun. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2024-11038
The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary shortcode execution via wpb_pcf_fire_contact_form AJAX action in all versions up to, and including, 1.7.5. ... Read more
- Published: Nov. 19, 2024
- Modified: Jul. 09, 2025