Latest CVE Feed
-
6.5
CVSS31CVE-2025-47504
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Custom Checkout Fields for WooCommerce allows Stored XSS. This issue affects Custom Checkout Fields for WooCommerce: from n/a through 1.8.3.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.7
CVSS31CVE-2025-47454
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Dynamics CRM allows Phishing. This issue affects WP Gravity Forms Dynamics CRM: from n/a through 1.1.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
9.3
CVSS31CVE-2025-2777
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47495
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blockspare Blockspare allows Stored XSS. This issue affects Blockspare: from n/a through 3.2.9.... Read more
Affected Products : blockspare- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.3
CVSS31CVE-2025-47485
Missing Authorization vulnerability in CozyThemes Cozy Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cozy Blocks: from n/a through 2.1.22.... Read more
Affected Products : cozy_blocks- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.9
CVSS31CVE-2025-47464
Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra allows Server Side Request Forgery. This issue affects Solace Extra: from n/a through 1.3.1.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47442
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CC CC BMI Calculator allows Stored XSS. This issue affects CC BMI Calculator: from n/a through 2.1.0.... Read more
Affected Products : cc_bmi_calculator- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47547
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter allows Stored XSS. This issue affects SendPulse Email Marketing Newsletter: from n/a through 2.1.6.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47519
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal Events allows Cross Site Request Forgery. This issue affects Easy PayPal Events: from n/a through 1.2.2.... Read more
Affected Products : easy_paypal_events- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47523
Cross-Site Request Forgery (CSRF) vulnerability in Lukáš Hartmann Seznam Webmaster allows Cross Site Request Forgery. This issue affects Seznam Webmaster: from n/a through 1.4.7.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.6
CVSS31CVE-2025-29152
Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via multiple components, including Strategic Planning Perspective Registration, Training Request, Perspective Editing, Education Reg... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47542
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.5.... Read more
Affected Products : simple_calendar_for_elementor- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.9
CVSS31CVE-2025-47516
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Time Clock allows Stored XSS. This issue affects Time Clock: from n/a through 1.2.3.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.9
CVSS31CVE-2025-47524
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karim42 Quran multilanguage Text & Audio allows Stored XSS. This issue affects Quran multilanguage Text & Audio: from n/a through 2.3.23.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.6
CVSS31CVE-2025-47537
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF Invoices for WooCommerce + Drag and Drop Template Builder allows SQL Injection. This issue affects PDF Invoices for WooCommerce + Drag an... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.9
CVSS31CVE-2025-47521
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery allows Stored XSS. This issue affects Robo Gallery: from n/a through 5.0.2.... Read more
Affected Products : robo_gallery- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.5
CVSS31CVE-2025-47510
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fullworks Display Eventbrite Events allows PHP Local File Inclusion. This issue affects Display Eventbrite Events: from n/a through n/... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47497
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepoints Logo Showcase allows DOM-Based XSS. This issue affects Logo Showcase: from n/a through 3.0.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47493
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks allows DOM-Based XSS. This issue affects Ultimate Blocks: from n/a through 3.2.9.... Read more
Affected Products : ultimate_blocks- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.4
CVSS31CVE-2025-47484
Server-Side Request Forgery (SSRF) vulnerability in Oliver Campion Display Remote Posts Block allows Server Side Request Forgery. This issue affects Display Remote Posts Block: from n/a through 1.1.0.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025