Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-68574

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows DOM-Based XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3.

PUBLISHED
Vendor
voidcoders
Product
WPBakery Visual Composer WHMCS Elements
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68573

Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.This issue affects Simple Keyword to Link: from n/a through <= 1.5.

PUBLISHED
Vendor
Alessandro Piconi
Product
Simple Keyword to Link
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68572

Missing Authorization vulnerability in Spider Themes BBP Core bbp-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BBP Core: from n/a through <= 1.4.1.

PUBLISHED
Vendor
Spider Themes
Product
BBP Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68571

Missing Authorization vulnerability in SALESmanago SALESmanago & Leadoo salesmanago allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SALESmanago & Leadoo: from n/a through <= 3.9.0.

PUBLISHED
Vendor
SALESmanago
Product
SALESmanago & Leadoo
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68570

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through <= 3.2.2.

PUBLISHED
Vendor
captivateaudio
Product
Captivate Sync
Provider severity
HIGH
Conflicts
0

CVE-2025-6857

A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5G__node_cmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
HDF5
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-68569

Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.39.

PUBLISHED
Vendor
codepeople
Product
WP Time Slots Booking Form
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68568

Missing Authorization vulnerability in Claspo Popup Builders Claspo – Popups, Spin the Wheel & Email Capture claspo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Claspo – Popups, Spin the Wheel & Email Capture: from n/a through <= 1.0.7.

PUBLISHED
Vendor
Claspo Popup Builders
Product
Claspo – Popups, Spin the Wheel & Email Capture
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68567

Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Cross Site Request Forgery.This issue affects My auctions allegro: from n/a through <= 3.6.33.

PUBLISHED
Vendor
wphocus
Product
My auctions allegro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68566

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Stored XSS.This issue affects My auctions allegro: from n/a through <= 3.6.35.

PUBLISHED
Vendor
wphocus
Product
My auctions allegro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68565

Missing Authorization vulnerability in JayBee Twitch Player ttv-easy-embed-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Twitch Player: from n/a through <= 2.1.3.

PUBLISHED
Vendor
JayBee
Product
Twitch Player
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68564

Missing Authorization vulnerability in sendy Sendy sendy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sendy: from n/a through <= 3.4.2.

PUBLISHED
Vendor
sendy
Product
Sendy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68563

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Unlock Lite subscribe-to-unlock-lite allows PHP Local File Inclusion.This issue affects Subscribe to Unlock Lite: from n/a through <= 1.3.0.

PUBLISHED
Vendor
WP Shuffle
Product
Subscribe to Unlock Lite
Provider severity
HIGH
Conflicts
0

CVE-2025-68562

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through 8.7.3.

PUBLISHED
Vendor
RomanCode
Product
MapSVG
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68561

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.4.

PUBLISHED
Vendor
Ruben Garcia
Product
AutomatorWP
Provider severity
HIGH
Conflicts
0

CVE-2025-68560

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1.

PUBLISHED
Vendor
CodexThemes
Product
TheGem Theme Elements (for Elementor)
Provider severity
HIGH
Conflicts
0

CVE-2025-6856

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_list of the file src/H5FL.c. The manipulation leads to use after free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
HDF5
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-68559

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1.

PUBLISHED
Vendor
CodexThemes
Product
TheGem Theme Elements (for Elementor)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68558

Missing Authorization vulnerability in averta Depicter Slider depicter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Depicter Slider: from n/a through <= 4.0.4.

PUBLISHED
Vendor
averta
Product
Depicter Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68557

Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chakra test: from n/a through <= 1.0.1.

PUBLISHED
Vendor
Vikas Ratudi
Product
Chakra test
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68556

Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.9.

PUBLISHED
Vendor
VillaTheme
Product
HAPPY
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68555

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affects Nutrie: from n/a through < 2.0.1.

PUBLISHED
Vendor
zozothemes
Product
Nutrie
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68554

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarch: from n/a through < 2.0.1.

PUBLISHED
Vendor
zozothemes
Product
Keenarch
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68553

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affects Lendiz: from n/a through < 2.0.1.

PUBLISHED
Vendor
zozothemes
Product
Lendiz
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68552

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countdown woo-coming-soon-product allows PHP Local File Inclusion.This issue affects WooCommerce Coming Soon Product with Countdown: from n/a through <= 5.0.

PUBLISHED
Vendor
WebCodingPlace
Product
WooCommerce Coming Soon Product with Countdown
Provider severity
HIGH
Conflicts
0

CVE-2025-68551

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form allows Retrieve Embedded Sensitive Data.This issue affects VPSUForm: from n/a through <= 3.2.24.

PUBLISHED
Vendor
Vikas Ratudi
Product
VPSUForm
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68550

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky wpbulky-wp-bulk-edit-post-types allows Blind SQL Injection.This issue affects WPBulky: from n/a through <= 1.1.13.

PUBLISHED
Vendor
VillaTheme
Product
WPBulky
Provider severity
HIGH
Conflicts
0

CVE-2025-6855

A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation of the argument flag leads to path traversal. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
chatchat-space
Product
Langchain-Chatchat
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68549

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to a Web Server.This issue affects Wiguard: from n/a through < 2.0.1.

PUBLISHED
Vendor
zozothemes
Product
Wiguard
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68548

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Stored XSS.This issue affects Responsive Posts Carousel Pro: from n/a through <= 15.2.

PUBLISHED
Vendor
WebCodingPlace
Product
Responsive Posts Carousel Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68547

Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Follow My Blog Post: from n/a through <= 2.4.0.

PUBLISHED
Vendor
wpweb
Product
Follow My Blog Post
Provider severity
HIGH
Conflicts
0

CVE-2025-68546

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local File Inclusion.This issue affects Nika: from n/a through <= 1.2.14.

PUBLISHED
Vendor
thembay
Product
Nika
Provider severity
HIGH
Conflicts
0

CVE-2025-68545

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local File Inclusion.This issue affects Nika: from n/a through <= 1.2.14.

PUBLISHED
Vendor
thembay
Product
Nika
Provider severity
HIGH
Conflicts
0

CVE-2025-68544

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local File Inclusion.This issue affects Diza: from n/a through <= 1.3.15.

PUBLISHED
Vendor
thembay
Product
Diza
Provider severity
HIGH
Conflicts
0

CVE-2025-68543

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local File Inclusion.This issue affects Diza: from n/a through <= 1.3.15.

PUBLISHED
Vendor
thembay
Product
Diza
Provider severity
HIGH
Conflicts
0

CVE-2025-68542

Missing Authorization vulnerability in vgdevsolutions Checkout Gateway for IRIS checkout-gateway-iris allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout Gateway for IRIS: from n/a through <= 1.3.

PUBLISHED
Vendor
vgdevsolutions
Product
Checkout Gateway for IRIS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68541

Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects Ippsum: from n/a through <= 1.2.0.

PUBLISHED
Vendor
BoldThemes
Product
Ippsum
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68540

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.35.

PUBLISHED
Vendor
thembay
Product
Fana
Provider severity
HIGH
Conflicts
0

CVE-2025-6854

A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
chatchat-space
Product
Langchain-Chatchat
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68539

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.35.

PUBLISHED
Vendor
thembay
Product
Fana
Provider severity
HIGH
Conflicts
0

CVE-2025-68538

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Craft craftcoffee allows DOM-Based XSS.This issue affects Craft: from n/a through <= 2.3.6.

PUBLISHED
Vendor
ThemeGoods
Product
Craft
Provider severity
HIGH
Conflicts
0

CVE-2025-68537

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14.

PUBLISHED
Vendor
thembay
Product
Zota
Provider severity
HIGH
Conflicts
0

CVE-2025-68536

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14.

PUBLISHED
Vendor
thembay
Product
Zota
Provider severity
HIGH
Conflicts
0

CVE-2025-68535

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.1.

PUBLISHED
Vendor
sunshinephotocart
Product
Sunshine Photo Cart
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68534

Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for WPForms: from n/a through <= 6.3.0.

PUBLISHED
Vendor
add-ons.org
Product
PDF for WPForms
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68533

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WC Builder wc-builder allows Stored XSS.This issue affects WC Builder: from n/a through <= 1.2.0.

PUBLISHED
Vendor
HasThemes
Product
WC Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68532

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Stored XSS.This issue affects ModelTheme Addons for WPBakery and Elementor: from n/a through < 1.5.6.

PUBLISHED
Vendor
modeltheme
Product
ModelTheme Addons for WPBakery and Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68531

Deserialization of Untrusted Data vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Object Injection.This issue affects ModelTheme Addons for WPBakery and Elementor: from n/a through < 1.5.6.

PUBLISHED
Vendor
modeltheme
Product
ModelTheme Addons for WPBakery and Elementor
Provider severity
HIGH
Conflicts
0

CVE-2025-68530

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Bookory bookory allows PHP Local File Inclusion.This issue affects Bookory: from n/a through <= 2.2.7.

PUBLISHED
Vendor
pavothemes
Product
Bookory
Provider severity
HIGH
Conflicts
0

CVE-2025-6853

A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend. The manipulation of the argument flag leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
chatchat-space
Product
Langchain-Chatchat
Provider severity
MEDIUM
Conflicts
1