Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-9256

WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.

PUBLISHED
Vendor
Uniong
Product
WebITR
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2025-9255

WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

PUBLISHED
Vendor
Uniong
Product
WebITR
Provider severity
HIGH
Conflicts
1

CVE-2025-9254

WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific functionality.

PUBLISHED
Vendor
Uniong
Product
WebITR
Provider severity
CRITICAL
Conflicts
1

CVE-2025-9253

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function RP_doSpecifySiteSurvey of the file /goform/RP_doSpecifySiteSurvey. The manipulation of the argument ssidhex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but di

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6350, RE6250, RE6300, RE7000, RE6500, RE9000
Provider severity
HIGH
Conflicts
3

CVE-2025-9252

A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function DisablePasswordAlertRedirect of the file /goform/DisablePasswordAlertRedirect. Executing manipulation of the argument hint can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted earl

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE9000, RE7000, RE6300, RE6350, RE6250, RE6500
Provider severity
HIGH
Conflicts
3

CVE-2025-9251

A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function sta_wps_pin of the file /goform/sta_wps_pin. Performing manipulation of the argument Ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6250, RE7000, RE9000, RE6300, RE6500, RE6350
Provider severity
HIGH
Conflicts
3

CVE-2025-9250

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts the function setPWDbyBBS of the file /goform/setPWDbyBBS. Such manipulation of the argument hint leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE7000, RE9000, RE6300, RE6350, RE6250, RE6500
Provider severity
HIGH
Conflicts
3

CVE-2025-9249

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function DHCPReserveAddGroup of the file /goform/DHCPReserveAddGroup. This manipulation of the argument enable_group/name_group/ip_group/mac_group causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE9000, RE6350, RE7000, RE6250, RE6500, RE6300
Provider severity
HIGH
Conflicts
3

CVE-2025-9248

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted element is the function RP_pingGatewayByBBS of the file /goform/RP_pingGatewayByBBS. The manipulation of the argument ssidhex results in stack-based buffer overflow. The attack may be performed from a remote location. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6350, RE6250, RE9000, RE6500, RE7000, RE6300
Provider severity
HIGH
Conflicts
3

CVE-2025-9247

A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affected element is the function setVlan of the file /goform/setVlan. The manipulation of the argument vlan_set leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6250, RE6350, RE6300, RE6500, RE7000, RE9000
Provider severity
HIGH
Conflicts
3

CVE-2025-9246

A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Impacted is the function check_port_conflict of the file /goform/check_port_conflict. Executing manipulation of the argument single_port_rule/port_range_rule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6500, RE7000, RE6350, RE9000, RE6250, RE6300
Provider severity
HIGH
Conflicts
3

CVE-2025-9245

A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function WPSSTAPINEnr of the file /goform/WPSSTAPINEnr. Performing manipulation of the argument ssid results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE7000, RE6500, RE6250, RE9000, RE6300, RE6350
Provider severity
HIGH
Conflicts
3

CVE-2025-9244

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaticRoute of the file /goform/addStaticRoute. Such manipulation of the argument staticRoute_IP_setting/staticRoute_Netmask_setting/staticRoute_Gateway_setting/staticRoute_Metric_setting/staticRoute_destType_setting leads to os command injection. The attack may be launched remotely. The exploit

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE7000, RE6250, RE6350, RE6500, RE6300, RE9000
Provider severity
MEDIUM
Conflicts
3

CVE-2025-9243

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capability check on the get_cc_orders and update_order_status functions in all versions up to, and including, 3.5.32. This makes it possible for authenticated attackers, with Subscriber-level access and above, to access order management functions and modify order status.

PUBLISHED
Vendor
stylemix
Product
Cost Calculator Builder
Provider severity
HIGH
Conflicts
0

CVE-2025-9242

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1.

PUBLISHEDCISA KEV
Vendor
WatchGuard
Product
Fireware OS
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9241

A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
elunez
Product
eladmin
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9240

A security flaw has been discovered in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file /auth/info. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
elunez
Product
eladmin
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9239

A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function EncryptUtils of the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java of the component DES Key Handler. The manipulation of the argument STR_PARAM with the input Passw0rd leads to inadequate encryption strength. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitation appears to be difficult.

PUBLISHED
Vendor
elunez
Product
eladmin
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9238

A vulnerability was determined in Swatadru Exam-Seating-Arrangement up to 97335ccebf95468d92525f4255a2241d2b0b002f. Affected is an unknown function of the file /student.php of the component Student Login. Executing manipulation of the argument email can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for a

PUBLISHED
Vendor
Swatadru
Product
Exam-Seating-Arrangement
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9237

A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of the component Edit Your Account Page. Performing manipulation of the argument Username results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
CodeAstro
Product
Ecommerce Website
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9236

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descrição leads to sql injection. The attack may be performed from a remote location. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9235

A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
n/a
Product
Scada-LTS
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9234

A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file maintenance_events.shtm. The manipulation of the argument Alias results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
n/a
Product
Scada-LTS
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9233

A security vulnerability has been detected in Scada-LTS up to 2.7.8.1. Impacted is an unknown function of the file view_edit.shtm. The manipulation of the argument Name leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
n/a
Product
Scada-LTS
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9232

Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate M

PUBLISHED
Vendor
Siemens, Siemens, Siemens, OpenSSL, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens
Product
SIMATIC CN 4100, SCALANCE XRM334 (230 V AC, 12xFO), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+), OpenSSL, SCALANCE XRM334 (2x230 V AC, 8xFO), RUGGEDCOM RST2428P, SCALANCE XCM332, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SCALANCE XCH328, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XRH334 (24 V DC, 8xFO, CC), SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, SCALANCE XRM334 (230 V AC, 8xFO), SCALANCE XRM334 (2x230 V AC, 12xFO), SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SCALANCE XRM334 (24 V DC, 12xFO), SIDIS Prime, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, RUGGEDCOM RST2428P, SCALANCE XRM334 (24 V DC, 8xFO), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+), SCALANCE XCM328, SCALANCE XCM324, SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+), SIDIS Secured SmartPlug
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9231

Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, OpenSSL, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens
Product
SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+), SCALANCE XRM334 (2x230 V AC, 8xFO), SCALANCE XCM328, SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+), SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM332, RUGGEDCOM RST2428P, SCALANCE XRM334 (230 V AC, 12xFO), OpenSSL, SCALANCE XRH334 (24 V DC, 8xFO, CC), SCALANCE XRM334 (24 V DC, 12xFO), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+), RUGGEDCOM RST2428P, SCALANCE XRM334 (2x230 V AC, 12xFO), SIMATIC CN 4100, SCALANCE XCM324, SCALANCE XRM334 (230 V AC, 8xFO), SCALANCE XCH328, SCALANCE XRM334 (24 V DC, 8xFO), SIDIS Secured SmartPlug
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9230

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, OpenSSL, Siemens, Siemens, Siemens, Siemens
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, SIDIS Prime, SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+), SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, RUGGEDCOM RST2428P, SIDIS Secured SmartPlug, SIMATIC CN 4100, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SCALANCE XCM332, SCALANCE XRH334 (24 V DC, 8xFO, CC), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+), SCALANCE XRM334 (230 V AC, 8xFO), SCALANCE XCM328, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, SCALANCE XRM334 (2x230 V AC, 12xFO), SCALANCE XCH328, RUGGEDCOM RST2428P, SCALANCE XRM334 (24 V DC, 12xFO), SCALANCE XRM334 (230 V AC, 12xFO), SCALANCE XCM324, OpenSSL, SCALANCE XRM334 (24 V DC, 8xFO), SCALANCE XRM334 (2x230 V AC, 8xFO), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+), SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Provider severity
HIGH
Conflicts
2

CVE-2025-9229

Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages.

PUBLISHED
Vendor
Mobile Industrial Robots, Mobile Industrial Robots
Product
MiR Fleet, MiR Robots
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9228

MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowing low-privilege users to create notes which are intended only for administrative users.

PUBLISHED
Vendor
Mobile Industrial Robots, Mobile Industrial Robots
Product
MiR Fleet, MiR Robots
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9227

Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine OpManager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9226

Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.

PUBLISHED
Vendor
Zohocorp, Zohocorp, Zohocorp
Product
ManageEngine OpManager, ManageEngine NetFlow Analyzer, ManageEngine OpUtils
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9225

Stored cross-site scripting (XSS) in the web interface of MiR software versions prior to 3.0.0 on MiR Robots and MiR Fleet allows execution of arbitrary JavaScript code in a victim’s browser

PUBLISHED
Vendor
Mobile Industrial Robots, Mobile Industrial Robots
Product
MiR Fleet, MiR Robots
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9223

Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine Applications Manager
Provider severity
HIGH
Conflicts
0

CVE-2025-9222

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

PUBLISHED
Vendor
Red Hat, Red Hat, GitLab, Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, GitLab, OpenShift Pipelines
Provider severity
HIGH
Conflicts
2

CVE-2025-9219

The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_post_smtp_pro_option_callback' function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable pro extensions.

PUBLISHED
Vendor
saadiqbal
Product
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9218

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media items associated with draft or private posts.

PUBLISHED
Vendor
rtcamp
Product
rtMedia for WordPress, BuddyPress and bbPress
Provider severity
LOW
Conflicts
0

CVE-2025-9217

The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_images' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PUBLISHED
Vendor
Revolution Slider
Product
Slider Revolution
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9216

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PUBLISHED
Vendor
kodezen
Product
StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More
Provider severity
HIGH
Conflicts
0

CVE-2025-9215

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the file_download() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PUBLISHED
Vendor
kodezen
Product
StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9214

A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service.

PUBLISHED
Vendor
Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo
Product
M7615DNA, M7626DNA Printer, M7686DXF, M7256WHF Printer, LJ2206W Printer, M7216NWA Printer, M7675DXF Printer, M7685DXF Printer, M7206W Printer, LJ2655DN Printer, M7628DNA Printer, M7455DNF Printer
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9213

The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due to missing or incorrect nonce validation on the 'handleToken' function. This makes it possible for unauthenticated attackers to update a user's authorization token via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Once the token is updated, an attacker can update the user's password and email address.

PUBLISHED
Vendor
textbuilder
Product
TextBuilder
Provider severity
HIGH
Conflicts
0

CVE-2025-9212

The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wp_dispatcher_process_upload() function in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The directory does have an .htaccess file which limits the ability to achieve remote code executio

PUBLISHED
Vendor
ekndev
Product
WP Dispatcher
Provider severity
HIGH
Conflicts
0

CVE-2025-9209

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT tokens for other users, including administrators, and authenticate as them.

PUBLISHED
Vendor
magnigenie
Product
RestroPress – Online Food Ordering System
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9208

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to compromise user sessions and data. This issue affects Web Site Management Server: 16.7.X, 16.8, 16.8.1.

PUBLISHED
Vendor
OpenText™
Product
Web Site Management Server
Provider severity
HIGH
Conflicts
0

CVE-2025-9207

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that can input and is later output. This makes it possible for unauthenticated attackers to inject arbitrary HTML into wishlist items.

PUBLISHED
Vendor
templateinvaders
Product
TI WooCommerce Wishlist
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9206

The Meks Easy Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title field in all version up to, and including, 2.1.4. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the map containing the malicious post.

PUBLISHED
Vendor
mekshq
Product
Meks Easy Maps
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9205

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
oyatek
Product
MapSVG – Vector maps, Image maps, Google Maps
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9204

The X Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Youtube Video ID field in all versions up to, and including, 1.0.16. This is due to insufficient input sanitization and output escaping on the Youtube Video ID parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an affected page.

PUBLISHED
Vendor
pencilwp
Product
X Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9203

The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitle_ssize', 'track_title', and 'track_artist_name' parameters in version 1.0.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
bplugins
Product
Media Player Addons for Elementor – Audio and Video Widgets for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9202

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the ThemeGrill Demo Importer plugin.

PUBLISHED
Vendor
themegrill
Product
ColorMag
Provider severity
MEDIUM
Conflicts
0