Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-8608

The Mihdan: Elementor Yandex Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 1.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
mihdan
Product
Maps from Yandex for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8607

The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block's attributes in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an inject

PUBLISHED
Vendor
amans2k
Product
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8606

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due to missing or incorrect nonce validation on the activate_plugin and deactivate_plugin functions. This makes it possible for attackers to trick authenticated administrators into activating or deactivating specified plugins via a forged request, such as clicking on a malicious link or visiting a compromised page.

PUBLISHED
Vendor
westerndeal
Product
GSheetConnector for Gravity Forms – Send Gravity Forms Entries to Google Sheets in Real-Time
Provider severity
LOW
Conflicts
0

CVE-2025-8605

The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
codeyatri
Product
Gutenify – Visual Site Builder Blocks & Site Templates.
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8604

The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wptb shortcode in all versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wptb
Product
WP Table Builder – Drag & Drop Table Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8603

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.148 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
unitecms
Product
Unlimited Elements For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8597

MacVim's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows local attackers with unprivileged access (e.g. via a malicious application) to attach a debugger, read or modify the process memory, inject code in the application's context despite being signed with Hardened Runtime and bypass Transparency, Consent, and Control (TCC). Acquired resource access is limited to previously granted permissions by the user. Access to other resources bey

PUBLISHED
Vendor
MacVim
Product
MacVim
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8595

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo settings.

PUBLISHED
Vendor
themegrill
Product
Zakra
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8594

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

PUBLISHED
Vendor
Unknown
Product
Pz-LinkCard
Provider severity
LOW
Conflicts
0

CVE-2025-8593

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to a missing capability check on the 'install_plugin' function. This makes it possible for authenticated attackers, with subscriber-level access and above to install plugins on the target site and potentially achieve arbitrary code execution on the server under certain conditions.

PUBLISHED
Vendor
westerndeal
Product
GSheetConnector for Gravity Forms – Send Gravity Forms Entries to Google Sheets in Real-Time
Provider severity
HIGH
Conflicts
0

CVE-2025-8592

The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or incorrect nonce validation on the inspiro_install_plugin() function. This makes it possible for unauthenticated attackers to install plugins from the repository via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
wpzoom
Product
Inspiro
Provider severity
HIGH
Conflicts
0

CVE-2025-8591

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on sessio

PUBLISHED
Vendor
WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2
Product
WSO2 Open Banking IAM, WSO2 Open Banking AM, WSO2 Identity Server, WSO2 Universal Gateway, WSO2 API Control Plane, WSO2 API Manager, WSO2 Identity Server as Key Manager, WSO2 Traffic Manager
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8590

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows Directory Indexing. This issue affects SKSPro: through 07012026.

PUBLISHED
Vendor
AKCE Software Technology R&D Industry and Trade Inc.
Product
SKSPro
Provider severity
HIGH
Conflicts
0

CVE-2025-8589

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows Reflected XSS. This issue affects SKSPro: through 07012026.

PUBLISHED
Vendor
AKCE Software Technology R&D Industry and Trade Inc.
Product
SKSPro
Provider severity
HIGH
Conflicts
0

CVE-2025-8588

The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Marker Title' and 'Marker Description' parameters for the Maps block in versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
publishpress
Product
PublishPress Blocks – Block Controls, Block Visibility, Block Permissions
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8587

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows SQL Injection. This issue affects SKSPro: through 07012026.

PUBLISHED
Vendor
AKCE Software Technology R&D Industry and Trade Inc.
Product
SKSPro
Provider severity
HIGH
Conflicts
0

CVE-2025-8586

A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The bug was initially reported by the researcher to the wrong project. This vulnerability only affects products that are no longer

PUBLISHED
Vendor
n/a
Product
libav
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-8585

A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The bug was initially reported by the researcher to the wrong project. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
n/a
Product
libav
Provider severity
MEDIUM
Conflicts
2

CVE-2025-8584

A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function av_buffer_unref of the file libavutil/buffer.c of the component AVI File Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The bug was initially reported by the researcher to the wrong project. This vulnerability only affects products that are no longer supp

PUBLISHED
Vendor
n/a
Product
libav
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-8583

Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8582

Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8581

Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8580

Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8579

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8578

Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2025-8577

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8576

Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2025-8575

The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'lws_cl_delete_file' function in all versions up to, and including, 2.4.1.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PUBLISHED
Vendor
aurelienlws
Product
LWS Cleaner
Provider severity
HIGH
Conflicts
0

CVE-2025-8573

Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.  Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks sealldev  (Noah Cooper) for reporting via HackerOne.

PUBLISHED
Vendor
Concrete CMS
Product
Concrete CMS
Provider severity
LOW
Conflicts
0

CVE-2025-8572

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges, including administrator access.

PUBLISHED
Vendor
dreamstechnologies
Product
Truelysell Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-8571

Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversation Messages Dashboard Page. Unsanitized input could cause theft of session cookies or tokens, defacement of web content, redirection to malicious sites, and (if victim is an admin), the execution of unauthorized actions. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N.

PUBLISHED
Vendor
Concrete CMS
Product
Concrete CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8570

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.

PUBLISHED
Vendor
beyondcart
Product
BeyondCart Connector
Provider severity
CRITICAL
Conflicts
0

CVE-2025-8568

The GMap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘h’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
prabode
Product
GMap Generator
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8567

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
posimyththemes
Product
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8566

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in the CountUp and Google Maps Blocks in all versions up to, and including, 2.18.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
cssigniterteam
Product
GutenBee – Gutenberg Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8565

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the wplp_gdpr_install_plugin_ajax_handler() function in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to install arbitrary repository plugins.

PUBLISHED
Vendor
wplegalpages
Product
Privacy Policy Generator – WPLP Legal Pages
Provider severity
HIGH
Conflicts
0

CVE-2025-8564

The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
sonalsinha21
Product
SKT Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8562

The Custom Query Shortcode plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.4.0 via the 'lens' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of files on the server, which can contain sensitive information.

PUBLISHED
Vendor
peterhebert
Product
Custom Query Shortcode
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8561

The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
ovatheme
Product
Ova Advent
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8560

The FancyTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
ghosttoast
Product
FancyTabs
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8559

The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.1 via the 'theme' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of files on the server, which can contain sensitive information.

PUBLISHED
Vendor
sanzeeb3
Product
All in One Music Player
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8558

Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from receiving new events from affected agents, resulting in a partial loss of integrity and availability with no impact to confidentiality.

PUBLISHED
Vendor
Proofpoint
Product
Insider Threat Management (ITM) Server
Provider severity
LOW
Conflicts
0

CVE-2025-8557

An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orchestrator (LXCO) network segment may be able to manipulate the local device to create an alternate communication channel which could allow the attacker, under certain conditions, to directly interact with backend LXCO API services typically inaccessible to users. While access controls may limit the scope of interaction,

PUBLISHED
Vendor
Lenovo
Product
XClarity Orchestrator (LXCO)
Provider severity
HIGH
Conflicts
1

CVE-2025-8556

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift GitOps, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security 4, Red Hat Edge Manager preview, OpenShift Pipelines, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Security 4, Red Hat Developer Hub, Red Hat Edge Manager preview, OpenShift Pipelines, Red Hat Trusted Artifact Signer, Red Hat Edge Manager preview, OpenShift Pipelines, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4, OpenShift Pipelines, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Builds for Red Hat OpenShift, OpenShift Service Mesh 3, Red Hat Advanced Cluster Security 4, OpenShift Pipelines, OpenShift Pipelines, Red Hat Trusted Profile Analyzer, OpenShift Pipelines, Red Hat Enterprise Linux AI (RHEL AI), Red Hat Enterprise Linux AI (RHEL AI), OpenShift Pipelines, OpenShift Pipelines, OpenShift Service Mesh 3, Red Hat Developer Hub, Red Hat Edge Manager preview, OpenShift Service Mesh 3, Builds for Red Hat OpenShift, Red Hat Advanced Cluster Security 4, Multicluster Global Hub, Custom Metric Autoscaler operator for Red Hat Openshift, Builds for Red Hat OpenShift, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4, Red Hat Ceph Storage 8, OpenShift Serverless, Red Hat Edge Manager preview, OpenShift Pipelines, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Dev Workspaces Operator, OpenShift Pipelines, Red Hat OpenShift for Windows Containers, Red Hat OpenShift for Windows Containers, Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat OpenShift GitOps, OpenShift Pipelines, Red Hat Enterprise Linux 10, OpenShift Service Mesh 3, OpenShift Serverless, OpenShift Pipelines, Red Hat Edge Manager preview, Red Hat Edge Manager preview, Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat Edge Manager preview, OpenShift Pipelines, OpenShift Pipelines, OpenShift Serverless, Red Hat Trusted Application Pipeline, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux AI (RHEL AI), Custom Metric Autoscaler operator for Red Hat Openshift, OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI), Red Hat Enterprise Linux AI (RHEL AI), OpenShift Pipelines, Red Hat Advanced Cluster Management for Kubernetes 2, OpenShift Pipelines, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, OpenShift Service Mesh 3, Red Hat OpenShift GitOps, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux AI (RHEL AI), Red Hat OpenStack Platform 17.1, OpenShift Pipelines, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Builds for Red Hat OpenShift, Red Hat Ceph Storage 6, Builds for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Workspaces Operator, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer, OpenShift Pipelines, Red Hat Enterprise Linux AI (RHEL AI), Red Hat Enterprise Linux 9, Red Hat OpenStack Platform 17.1, Red Hat Advanced Cluster Security 4, OpenShift Pipelines, Red Hat Ceph Storage 6, OpenShift Pipelines, OpenShift Pipelines, OpenShift Service Mesh 3, OpenShift Pipelines, Red Hat Enterprise Linux AI (RHEL AI), Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager preview, OpenShift Service Mesh 3, Red Hat Enterprise Linux AI (RHEL AI), Red Hat Edge Manager preview, Custom Metric Autoscaler operator for Red Hat Openshift, OpenShift Pipelines, Red Hat Ceph Storage 8, Red Hat Trusted Artifact Signer, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat Trusted Artifact Signer, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Virtualization 4, Builds for Red Hat OpenShift, Red Hat OpenShift Dev Workspaces Operator, OpenShift Pipelines, Red Hat Ceph Storage 5, Red Hat Ceph Storage 5, Red Hat OpenShift GitOps, Red Hat OpenStack Platform 16.2
Provider severity
LOW
Conflicts
1

CVE-2025-8555

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown function of the file /search. The manipulation of the argument keyword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2fe4a51afbce0068c291bc1818bbc8f7f3b01a22. It is recommended to apply a patch to fix this issue.

PUBLISHED
Vendor
atjiu
Product
pybbs
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-8554

A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some unknown processing of the file /admin/user/list. The manipulation of the argument Username leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 2fe4a51afbce0068c291bc1818bbc8f7f3b01a22. It is recommended to apply a patch to fix this issue.

PUBLISHED
Vendor
atjiu
Product
pybbs
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-8553

A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code of the file /admin/sensitive_word/list. The manipulation of the argument word leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 2fe4a51afbce0068c291bc1818bbc8f7f3b01a22. It is recommended to apply a patch to fix this issue.

PUBLISHED
Vendor
atjiu
Product
pybbs
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-8552

A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the file /admin/tag/list. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 2fe4a51afbce0068c291bc1818bbc8f7f3b01a22. It is recommended to apply a patch to fix this issue.

PUBLISHED
Vendor
atjiu
Product
pybbs
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-8551

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/comment/list. The manipulation of the argument Username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2fe4a51afbce0068c291bc1818bbc8f7f3b01a22. It is recommended to apply a patch to fix this issue.

PUBLISHED
Vendor
atjiu
Product
pybbs
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-8550

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/topic/list. The manipulation of the argument Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named 2fe4a51afbce0068c291bc1818bbc8f7f3b01a22. It is recommended to apply a patch to fix this issue.

PUBLISHED
Vendor
atjiu
Product
pybbs
Provider severity
LOW, MEDIUM
Conflicts
2