Latest CVE Feed
-
7.1
HIGHCVE-2025-49274
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awplife Neom Blog allows Reflected XSS. This issue affects Neom Blog: from n/a through 0.0.9.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-49247
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Team Showcase allows DOM-Based XSS. This issue affects Team Showcase: from n/a through n/a.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-49245
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Testimonials Showcase allows Reflected XSS. This issue affects Testimonials Showcase: from n/a through 1.9.16.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2025-49070
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi allows PHP Local File Inclusion. This issue affects Elessi: from n/a through n/a.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.5
MEDIUMCVE-2025-48231
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.58.... Read more
Affected Products : booking_calendar- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.5
MEDIUMCVE-2025-47634
Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WC Pickup Store: from n/a through 1.8.9.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2025-47627
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail Actions allows PHP Local File Inclusion. This issue affects PrivateContent - Mail Actions: from n/a throug... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.3
MEDIUMCVE-2025-47565
Missing Authorization vulnerability in ashanjay EventON allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventON: from n/a through 4.9.9.... Read more
Affected Products : eventon-lite- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2025-47479
Weak Authentication vulnerability in AresIT WP Compress allows Authentication Abuse. This issue affects WP Compress: from n/a through 6.30.30.... Read more
Affected Products : wp_compress- Published: Jul. 04, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-39487
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie allows Reflected XSS. This issue affects Rankie: from n/a through 1.8.2.... Read more
Affected Products : rankie- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-32311
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Pressroom - News Magazine WordPress Theme allows Reflected XSS. This issue affects Pressroom - News Magazine WordPress Theme: from n/a throu... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
8.5
HIGHCVE-2025-32297
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory allows SQL Injection. This issue affects Simple Link Directory: from n/a through 14.7.3.... Read more
Affected Products : simple_link_directory- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-31037
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey allows Reflected XSS. This issue affects Homey: from n/a through 2.4.5.... Read more
Affected Products : homey- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
10.0
CRITICALCVE-2025-30933
Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub allows Upload a Web Shell to a Web Server. This issue affects LogisticsHub: from n/a through 1.1.6.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2025-28983
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.7
HIGHCVE-2025-28980
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA allows Path Traversal. This issue affects Aviation Weather from NOAA: from n/a through 0.7.2.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-28978
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hung Trang Si SB Breadcrumbs allows Reflected XSS. This issue affects SB Breadcrumbs: from n/a through 1.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.5
MEDIUMCVE-2025-28976
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dsrodzin Email Address Security by WebEmailProtector allows Stored XSS. This issue affects Email Address Security by WebEmailProtector: from n/a through ... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-28968
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac WP Wall allows Reflected XSS. This issue affects WP Wall: from n/a through 1.7.3.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
8.5
HIGHCVE-2025-24780
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows SQL Injection. This issue affects Printcart Web to Print Product Designer for Wo... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025