Latest CVE Feed
-
6.5
MEDIUMCVE-2025-47598
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in click5 History Log by click5 allows Stored XSS. This issue affects History Log by click5: from n/a through 1.0.13.... Read more
Affected Products : sitemap_by_click5- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-47561
Incorrect Privilege Assignment vulnerability in PT Norther Lights Production MapSVG allows Privilege Escalation.This issue affects MapSVG: from n/a before 8.6.13.... Read more
Affected Products : mapsvg- Published: Jun. 09, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-47527
Missing Authorization vulnerability in Icegram Icegram Collect – Easy Form, Lead Collection and Subscription plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Icegram Collect – Easy Form, Lead Collection an... Read more
Affected Products : icegram_collect- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
6.8
MEDIUMCVE-2025-47511
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nanbu Welcart e-Commerce allows Path Traversal. This issue affects Welcart e-Commerce: from n/a through 2.11.13.... Read more
Affected Products : welcart_e-commerce- Published: Jun. 09, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-47487
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moreconvert MC Woocommerce Wishlist allows Reflected XSS. This issue affects MC Woocommerce Wishlist: from n/a through 1.9.1.... Read more
Affected Products : woocommerce_wishlist- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-47477
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule allows Reflected XSS. This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.23.... Read more
Affected Products : backup_and_staging_by_wp_time_capsule- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-47463
Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Stock Locations for WooCommerce: from n/a through 2.8.6.... Read more
Affected Products : stock_locations_for_woocommerce- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-46178
Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, lea... Read more
Affected Products : cloudclassroom-php_project- Published: Jun. 09, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-45055
Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript ... Read more
Affected Products : silverpeas- Published: Jun. 09, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-39539
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quitenicestuff Soho Hotel allows Reflected XSS. This issue affects Soho Hotel: from n/a through 4.2.5.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-39476
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Revo allows PHP Local File Inclusion. This issue affects Revo: from n/a through 4.0.26.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-39475
Path Traversal vulnerability in Frenify Arlo allows PHP Local File Inclusion. This issue affects Arlo: from n/a through 6.0.3.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-39473
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebGeniusLab Seofy Core allows PHP Local File Inclusion. This issue affects Seofy Core: from n/a through 1.4.5.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-32595
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Krowd allows PHP Local File Inclusion. This issue affects Krowd: from n/a through 1.4.1.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
7.6
HIGHCVE-2025-32308
Missing Authorization vulnerability in looks_awesome Team Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Team Builder: from n/a through 1.5.7.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-32305
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sneeit FlatNews allows Reflected XSS. This issue affects FlatNews: from n/a through 5.8.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-32291
Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro allows Using Malicious Files. This issue affects SUMO Affiliates Pro: from n/a through 10.7.0.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-31925
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup SHOUT allows Reflected XSS. This issue affects SHOUT: from n/a through 3.5.3.... Read more
Affected Products : shout- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2025-31920
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech WP Guppy allows SQL Injection. This issue affects WP Guppy: from n/a through 4.3.3.... Read more
Affected Products : wp_guppy- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-31917
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player allows Reflected XSS. This issue affects Universal Video Player: from n/a through 3.8.3.... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting