Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-68908

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in temash Barberry barberry allows PHP Local File Inclusion.This issue affects Barberry: from n/a through <= 2.9.9.87.

PUBLISHED
Vendor
temash
Product
Barberry
Provider severity
HIGH
Conflicts
0

CVE-2025-68907

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Hostme v2 hostmev2 allows Path Traversal.This issue affects Hostme v2: from n/a through <= 7.0.

PUBLISHED
Vendor
AivahThemes
Product
Hostme v2
Provider severity
HIGH
Conflicts
0

CVE-2025-68906

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - Video jnews-video allows Reflected XSS.This issue affects JNews - Video: from n/a through <= 11.0.2.

PUBLISHED
Vendor
jegtheme
Product
JNews - Video
Provider severity
HIGH
Conflicts
0

CVE-2025-68905

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jegtheme JNews - Pay Writer jnews-pay-writer allows PHP Local File Inclusion.This issue affects JNews - Pay Writer: from n/a through <= 11.0.0.

PUBLISHED
Vendor
jegtheme
Product
JNews - Pay Writer
Provider severity
HIGH
Conflicts
0

CVE-2025-68904

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - Frontend Submit jnews-frontend-submit allows Reflected XSS.This issue affects JNews - Frontend Submit: from n/a through <= 11.0.0.

PUBLISHED
Vendor
jegtheme
Product
JNews - Frontend Submit
Provider severity
HIGH
Conflicts
0

CVE-2025-68903

Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0.

PUBLISHED
Vendor
AivahThemes
Product
Anona
Provider severity
HIGH
Conflicts
0

CVE-2025-68902

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affects Anona: from n/a through <= 8.0.

PUBLISHED
Vendor
AivahThemes
Product
Anona
Provider severity
HIGH
Conflicts
0

CVE-2025-68901

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affects Anona: from n/a through <= 8.0.

PUBLISHED
Vendor
AivahThemes
Product
Anona
Provider severity
HIGH
Conflicts
0

CVE-2025-68900

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allows DOM-Based XSS. This issue affects Enfold: from n/a through 7.1.3.

PUBLISHED
Vendor
Kriesi
Product
Enfold
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6890

A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /ticketConfirmation.php. The manipulation of the argument Date leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Movie Ticketing System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68899

Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= 2.4.

PUBLISHED
Vendor
designthemes
Product
Vivagh
Provider severity
HIGH
Conflicts
0

CVE-2025-68898

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cjjparadoxmax Synergy Project Manager synergy-project-manager allows Stored XSS.This issue affects Synergy Project Manager: from n/a through <= 1.5.

PUBLISHED
Vendor
cjjparadoxmax
Product
Synergy Project Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68897

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-shortcode allows Code Injection.This issue affects IF AS Shortcode: from n/a through <= 1.2.

PUBLISHED
Vendor
Mohammad I. Okfie
Product
IF AS Shortcode
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68896

Missing Authorization vulnerability in vrpr WDV One Page Docs wdv-one-page-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WDV One Page Docs: from n/a through <= 1.2.4.

PUBLISHED
Vendor
vrpr
Product
WDV One Page Docs
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68895

Authentication Bypass Using an Alternate Path or Channel vulnerability in ahachat AhaChat Messenger Marketing ahachat-messenger-marketing allows Password Recovery Exploitation.This issue affects AhaChat Messenger Marketing: from n/a through <= 1.1.

PUBLISHED
Vendor
ahachat
Product
AhaChat Messenger Marketing
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68894

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shoutoutglobal ShoutOut shoutout allows Reflected XSS.This issue affects ShoutOut: from n/a through <= 4.0.2.

PUBLISHED
Vendor
shoutoutglobal
Product
ShoutOut
Provider severity
HIGH
Conflicts
0

CVE-2025-68893

Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Side Request Forgery.This issue affects WordPress Image shrinker: from n/a through <= 1.1.0.

PUBLISHED
Vendor
HETWORKS
Product
WordPress Image shrinker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68892

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.com Scroll rss excerpt scroll-rss-excerpt allows Reflected XSS.This issue affects Scroll rss excerpt: from n/a through <= 5.0.

PUBLISHED
Vendor
gopiplus@hotmail.com
Product
Scroll rss excerpt
Provider severity
HIGH
Conflicts
0

CVE-2025-68891

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Sutana WP App Bar wp-app-bar allows Reflected XSS.This issue affects WP App Bar: from n/a through <= 1.5.

PUBLISHED
Vendor
Ryan Sutana
Product
WP App Bar
Provider severity
HIGH
Conflicts
0

CVE-2025-68890

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hands01 e-shops e-shops-cart2 allows DOM-Based XSS.This issue affects e-shops: from n/a through <= 1.0.4.

PUBLISHED
Vendor
hands01
Product
e-shops
Provider severity
HIGH
Conflicts
0

CVE-2025-6889

A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /logIn.php. The manipulation of the argument postName leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Movie Ticketing System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-68889

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pinpoll Pinpoll pinpoll allows Reflected XSS.This issue affects Pinpoll: from n/a through <= 4.0.0.

PUBLISHED
Vendor
Pinpoll
Product
Pinpoll
Provider severity
HIGH
Conflicts
0

CVE-2025-68887

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Reflected XSS.This issue affects WP-BusinessDirectory: from n/a through <= 4.0.1.

PUBLISHED
Vendor
CMSJunkie - WordPress Business Directory Plugins
Product
WP-BusinessDirectory
Provider severity
HIGH
Conflicts
0

CVE-2025-68886

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8.

PUBLISHED
Vendor
androThemes
Product
Cookiteer
Provider severity
HIGH
Conflicts
0

CVE-2025-68885

Cross-Site Request Forgery (CSRF) vulnerability in page-carbajal Custom Post Status custom-post-status allows Stored XSS.This issue affects Custom Post Status: from n/a through <= 1.1.0.

PUBLISHED
Vendor
page-carbajal
Product
Custom Post Status
Provider severity
HIGH
Conflicts
0

CVE-2025-68884

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arevico WP Simple Redirect wp-simple-redirect allows Reflected XSS.This issue affects WP Simple Redirect: from n/a through <= 1.1.

PUBLISHED
Vendor
Arevico
Product
WP Simple Redirect
Provider severity
HIGH
Conflicts
0

CVE-2025-68883

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extremeidea bidorbuy Store Integrator bidorbuystoreintegrator allows Reflected XSS.This issue affects bidorbuy Store Integrator: from n/a through <= 2.12.0.

PUBLISHED
Vendor
extremeidea
Product
bidorbuy Store Integrator
Provider severity
HIGH
Conflicts
0

CVE-2025-68882

Missing Authorization vulnerability in Scalenut Scalenut scalenut allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scalenut: from n/a through <= 1.1.5.

PUBLISHED
Vendor
Scalenut
Product
Scalenut
Provider severity
HIGH
Conflicts
0

CVE-2025-68881

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExperts appexperts allows SQL Injection.This issue affects AppExperts: from n/a through <= 1.4.5.

PUBLISHED
Vendor
Saad Iqbal
Product
AppExperts
Provider severity
HIGH
Conflicts
0

CVE-2025-68880

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allows Reflected XSS.This issue affects Simple Archive Generator: from n/a through <= 5.2.

PUBLISHED
Vendor
peterwsterling
Product
Simple Archive Generator
Provider severity
HIGH
Conflicts
0

CVE-2025-6888

A vulnerability was found in PHPGurukul Teachers Record Management System 2.1. It has been classified as critical. This affects an unknown part of the file /admin/changeimage.php. The manipulation of the argument tid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Teachers Record Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-68879

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Content Grid Slider content-grid-slider allows Reflected XSS.This issue affects Content Grid Slider: from n/a through <= 1.5.

PUBLISHED
Vendor
councilsoft
Product
Content Grid Slider
Provider severity
HIGH
Conflicts
0

CVE-2025-68878

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prasadkirpekar Advanced Custom CSS advanced-custom-css allows Reflected XSS.This issue affects Advanced Custom CSS: from n/a through <= 1.1.0.

PUBLISHED
Vendor
prasadkirpekar
Product
Advanced Custom CSS
Provider severity
HIGH
Conflicts
0

CVE-2025-68877

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce CedCommerce Integration for Good Market ced-good-market-integration allows PHP Local File Inclusion.This issue affects CedCommerce Integration for Good Market: from n/a through <= 1.0.6.

PUBLISHED
Vendor
cedcommerce
Product
CedCommerce Integration for Good Market
Provider severity
HIGH
Conflicts
0

CVE-2025-68876

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INVELITY Invelity SPS connect invelity-sps-connect allows Reflected XSS.This issue affects Invelity SPS connect: from n/a through <= 1.0.8.

PUBLISHED
Vendor
INVELITY
Product
Invelity SPS connect
Provider severity
HIGH
Conflicts
0

CVE-2025-68875

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming Password Reset flaming-password-reset allows Stored XSS.This issue affects Flaming Password Reset: from n/a through <= 1.0.3.

PUBLISHED
Vendor
jcaruso001
Product
Flaming Password Reset
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68874

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Visitor Stats Widget visitor-stats-widget allows Reflected XSS.This issue affects Visitor Stats Widget: from n/a through <= 1.5.0.

PUBLISHED
Vendor
Shahjada
Product
Visitor Stats Widget
Provider severity
HIGH
Conflicts
0

CVE-2025-68873

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chloédigital PRIMER by chloédigital primer-by-chloedigital allows Reflected XSS.This issue affects PRIMER by chloédigital: from n/a through <= 1.0.25.

PUBLISHED
Vendor
chloédigital
Product
PRIMER by chloédigital
Provider severity
HIGH
Conflicts
0

CVE-2025-68872

Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.

PUBLISHED
Vendor
Eli
Product
Eli&#039;s WordCents adSense Widget with Analytics
Provider severity
HIGH
Conflicts
0

CVE-2025-68871

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in noCreativity Dooodl dooodl allows Reflected XSS.This issue affects Dooodl: from n/a through <= 2.3.0.

PUBLISHED
Vendor
noCreativity
Product
Dooodl
Provider severity
HIGH
Conflicts
0

CVE-2025-68870

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in reDim GmbH CookieHint WP cookiehint-wp allows PHP Local File Inclusion.This issue affects CookieHint WP: from n/a through <= 1.0.0.

PUBLISHED
Vendor
reDim GmbH
Product
CookieHint WP
Provider severity
HIGH
Conflicts
0

CVE-2025-6887

A vulnerability was found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/SetSysTimeCfg. The manipulation of the argument time/timeZone leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
AC5
Provider severity
HIGH
Conflicts
2

CVE-2025-68869

Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privilege Escalation.This issue affects LazyTasks: from n/a through <= 1.2.37.

PUBLISHED
Vendor
LazyCoders LLC
Product
LazyTasks
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68868

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Text Slider Widget wp-text-slider-widget allows Stored XSS.This issue affects Wp Text Slider Widget: from n/a through <= 1.0.

PUBLISHED
Vendor
codeaffairs
Product
Wp Text Slider Widget
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68867

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anibalwainstein Effect Maker effect-maker allows DOM-Based XSS.This issue affects Effect Maker: from n/a through <= 1.2.1.

PUBLISHED
Vendor
anibalwainstein
Product
Effect Maker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68866

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woofer696 Dinatur dinatur allows Stored XSS.This issue affects Dinatur: from n/a through <= 1.18.

PUBLISHED
Vendor
woofer696
Product
Dinatur
Provider severity
HIGH
Conflicts
0

CVE-2025-68865

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injection.This issue affects Infility Global: from n/a through <= 2.15.06.

PUBLISHED
Vendor
Infility
Product
Infility Global
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68864

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global infility-global allows Stored XSS.This issue affects Infility Global: from n/a through <= 2.15.11.

PUBLISHED
Vendor
Infility
Product
Infility Global
Provider severity
HIGH
Conflicts
0

CVE-2025-68863

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz iContact for Gravity Forms gravity-forms-icontact allows Reflected XSS.This issue affects iContact for Gravity Forms: from n/a through <= 1.3.2.

PUBLISHED
Vendor
Zack Katz
Product
iContact for Gravity Forms
Provider severity
HIGH
Conflicts
0

CVE-2025-68862

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Murtaza Bhurgri Woo File Dropzone woo-file-dropzone allows Path Traversal.This issue affects Woo File Dropzone: from n/a through <= 1.1.7.

PUBLISHED
Vendor
Murtaza Bhurgri
Product
Woo File Dropzone
Provider severity
HIGH
Conflicts
0