Latest CVE Feed
-
9.9
CRITICALCVE-2025-49013
WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user controlled variables... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-48877
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, Codepen is present in the default `allowed_iframes` site se... Read more
Affected Products : discourse- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-48129
Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows Privilege Escalation. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: fro... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-48125
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Event Manager WP Event Manager allows PHP Local File Inclusion. This issue affects WP Event Manager: from n/a through 3.1.49.... Read more
Affected Products : wp_event_manager- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-48143
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salesup2019 Formulario de contacto SalesUp! allows Reflected XSS. This issue affects Formulario de contacto SalesUp!: from n/a through 1.0.14.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-48053
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, sending a malicious URL in a PM to a bot user can cause a r... Read more
Affected Products : discourse- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-48130
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spicethemes Spice Blocks allows Path Traversal. This issue affects Spice Blocks: from n/a through 2.0.7.2.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-47463
Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Stock Locations for WooCommerce: from n/a through 2.8.6.... Read more
Affected Products : stock_locations_for_woocommerce- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-47477
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule allows Reflected XSS. This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.23.... Read more
Affected Products : backup_and_staging_by_wp_time_capsule- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-40668
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a POST request using the parameters idUser, PasswordActual, PasswordNew and PasswordNe... Read more
Affected Products : gim- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-40670
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to /PC/frmGestionUser.aspx/updateUser.... Read more
Affected Products : gim- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-32595
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Krowd allows PHP Local File Inclusion. This issue affects Krowd: from n/a through 1.4.1.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-31426
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Sticky Radio Player allows Reflected XSS. This issue affects Sticky Radio Player: from n/a through 3.4.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-31398
Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This issue affects PIMP - Creative MultiPurpose: from n/a through 1.7.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-31429
Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This issue affects PressGrid - Frontend Publish Reaction & Multimedia Theme: from n/a through 1.3.1.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-31057
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player allows Reflected XSS. This issue affects Universal Video Player: from n/a through 1.4.0.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-31045
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in elfsight elfsight Contact Form widget allows Retrieve Embedded Sensitive Data. This issue affects elfsight Contact Form widget: from n/a through 2.3.1.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-5890
A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expressi... Read more
Affected Products : toolkit- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-5888
A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit ... Read more
Affected Products : webstack-guns- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-49652
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication