Latest CVE Feed
-
7.5
HIGHCVE-2025-58767
REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or l... Read more
Affected Products : rexml- Published: Sep. 17, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2025-9993
The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inc... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-9991
The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2025-9948
The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing or incorrect nonce validation on the admin settings page. This makes it possible for unauthenticated a... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-9946
The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthen... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2025-9852
The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-schedule' shortcode in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping on user supp... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-9762
The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the save_attachments function in all versions up to, and including, 1.0.4b. This makes it possible for unauthenticated attackers to uploa... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-8877
The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in all versions up to, and including, 2.28.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparati... Read more
Affected Products : affiliatewp- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-8777
The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8625
The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function in versions 1.1 to 1.2. The plugin falls back to a hard-coded JWT signing key when no secret is defined and does not restrict which fil... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-8624
The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This ... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-8623
The WeedMaps Menu for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's weedmaps_menu shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user suppl... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-8608
The Mihdan: Elementor Yandex Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 1.6.11 due to insufficient input sanitization and output escaping on user supplied ... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-8566
The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in the CountUp and Google Maps Blocks in all versions up to, and including, 2.18.0 due to insufficient input sanitization and output escaping.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-8560
The FancyTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-8559
The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.1 via the 'theme' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to read th... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Path Traversal
-
6.4
MEDIUMCVE-2025-8214
The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typing Letter widget in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping on user supplied at... Read more
Affected Products : the_pack_elementor_addons- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-8122
Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publi... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2025-8121
Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publi... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-8120
Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication