Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-68529

Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery.This issue affects WP Email Capture: from n/a through <= 3.12.5.

PUBLISHED
Vendor
Rhys Wynne
Product
WP Email Capture
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68528

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce amount-left-free-shipping-woocommerce allows Stored XSS.This issue affects Free Shipping Bar: Amount Left for Free Shipping for WooCommerce: from n/a through <= 2.4.9.

PUBLISHED
Vendor
WPFactory
Product
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68527

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC Academy LMS academy allows Stored XSS.This issue affects Academy LMS: from n/a through <= 3.4.0.

PUBLISHED
Vendor
Kodezen LLC
Product
Academy LMS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68526

Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup Box: from n/a through <= 1.6.1.

PUBLISHED
Vendor
A WP Life
Product
Modal Popup Box
Provider severity
HIGH
Conflicts
0

CVE-2025-68525

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Category Icon category-icon allows Stored XSS.This issue affects Category Icon: from n/a through <= 1.0.2.

PUBLISHED
Vendor
pixelgrade
Product
Category Icon
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68524

Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.

PUBLISHED
Vendor
ThemeGoods
Product
Avante
Provider severity
HIGH
Conflicts
0

CVE-2025-68523

Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spiffy Calendar: from n/a through <= 5.0.7.

PUBLISHED
Vendor
Spiffy Plugins
Product
Spiffy Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68522

Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through <= 4.9.5.

PUBLISHED
Vendor
wpstream
Product
WpStream
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68521

Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through <= 4.9.5.

PUBLISHED
Vendor
wpstream
Product
WpStream
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68520

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods DotLife dotlife allows Reflected XSS.This issue affects DotLife: from n/a through < 4.9.5.

PUBLISHED
Vendor
ThemeGoods
Product
DotLife
Provider severity
HIGH
Conflicts
0

CVE-2025-68519

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Blind SQL Injection.This issue affects Brands for WooCommerce: from n/a through <= 3.8.6.3.

PUBLISHED
Vendor
BeRocket
Product
Brands for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-68518

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Hoteller hoteller allows Reflected XSS.This issue affects Hoteller: from n/a through < 6.8.9.

PUBLISHED
Vendor
ThemeGoods
Product
Hoteller
Provider severity
HIGH
Conflicts
0

CVE-2025-68517

Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.1.35.1.

PUBLISHED
Vendor
Essekia
Product
Tablesome
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68516

Insertion of Sensitive Information Into Sent Data vulnerability in Essekia Tablesome tablesome allows Retrieve Embedded Sensitive Data.This issue affects Tablesome: from n/a through <= 1.1.35.1.

PUBLISHED
Vendor
Essekia
Product
Tablesome
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68515

Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allows Retrieve Embedded Sensitive Data.This issue affects WP Booking System: from n/a through <= 2.0.19.12.

PUBLISHED
Vendor
Roland Murg
Product
WP Booking System
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68514

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8.

PUBLISHED
Vendor
Cozmoslabs
Product
Paid Member Subscriptions
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68513

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Timeline Lite bold-timeline-lite allows Stored XSS.This issue affects Bold Timeline Lite: from n/a through <= 1.2.7.

PUBLISHED
Vendor
boldthemes
Product
Bold Timeline Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68512

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Stored XSS.This issue affects Real 3D FlipBook: from n/a through <= 4.11.4.

PUBLISHED
Vendor
creativeinteractivemedia
Product
Real 3D FlipBook
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68511

Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse Form: from n/a through <= 2.3.1.

PUBLISHED
Vendor
Jegstudio
Product
Gutenverse Form
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68510

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeGoods Photography photography allows PHP Local File Inclusion.This issue affects Photography: from n/a through < 7.7.5.

PUBLISHED
Vendor
ThemeGoods
Product
Photography
Provider severity
HIGH
Conflicts
0

CVE-2025-6851

The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function which ultimately calls the check_url_status_code() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PUBLISHED
Vendor
apos37
Product
Broken Link Notifier
Provider severity
HIGH
Conflicts
0

CVE-2025-68509

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-posts allows Phishing.This issue affects User Submitted Posts: from n/a through <= 20251121.

PUBLISHED
Vendor
Jeff Starr
Product
User Submitted Posts
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68508

Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brave: from n/a through <= 0.8.3.

PUBLISHED
Vendor
Brave
Product
Brave
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68507

Missing Authorization vulnerability in Icegram Icegram icegram allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Icegram: from n/a through <= 3.1.35.

PUBLISHED
Vendor
Icegram
Product
Icegram
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68506

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache docket-cache allows PHP Local File Inclusion.This issue affects Docket Cache: from n/a through <= 24.07.03.

PUBLISHED
Vendor
Nawawi Jamili
Product
Docket Cache
Provider severity
HIGH
Conflicts
0

CVE-2025-68505

Missing Authorization vulnerability in icc0rz H5P h5p allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects H5P: from n/a through <= 1.16.1.

PUBLISHED
Vendor
icc0rz
Product
H5P
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68504

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= 3.5.16.

PUBLISHED
Vendor
Crocoblock
Product
JetSearch
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68503

Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through <= 2.4.7.

PUBLISHED
Vendor
Crocoblock
Product
JetBlog
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68502

Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetPopup: from n/a through <= 2.0.20.1.

PUBLISHED
Vendor
Crocoblock
Product
JetPopup
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68501

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce allows Reflected XSS.This issue affects Mollie Payments for WooCommerce: from n/a through <= 8.1.1.

PUBLISHED
Vendor
Mollie
Product
Mollie Payments for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-68500

Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Server Side Request Forgery.This issue affects Prime Slider – Addons For Elementor: from n/a through <= 4.0.10.

PUBLISHED
Vendor
bdthemes
Product
Prime Slider – Addons For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6850

A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forum1.php. The manipulation of the argument File leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Forum
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68499

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.12.

PUBLISHED
Vendor
Crocoblock
Product
JetTabs
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68498

Missing Authorization vulnerability in Crocoblock JetTabs jet-tabs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetTabs: from n/a through <= 2.2.12.

PUBLISHED
Vendor
Crocoblock
Product
JetTabs
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68497

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.16.

PUBLISHED
Vendor
Brainstorm Force
Product
Astra Widgets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68496

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.0.

PUBLISHED
Vendor
Syed Balkhi
Product
User Feedback
Provider severity
HIGH
Conflicts
0

CVE-2025-68495

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0.

PUBLISHED
Vendor
Crocoblock
Product
JetEngine
Provider severity
HIGH
Conflicts
0

CVE-2025-68494

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Premium Addons for Elementor: from n/a through <= 4.11.53.

PUBLISHED
Vendor
Leap13
Product
Premium Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68493

An XML processing flaw has been found in Apache Struts. Parsing of XML configuration in the XWork component does not validate XML in proper way and it's vulnerable to XML external entity (XXE) injection.

PUBLISHED
Vendor
Apache Software Foundation, Red Hat, Red Hat, Apache Software Foundation, Red Hat, Red Hat
Product
Apache Struts, Red Hat Fuse 7, Red Hat Enterprise Linux 8, Apache Struts, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8
Provider severity
HIGH
Conflicts
3

CVE-2025-68492

Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.

PUBLISHED
Vendor
Chainlit
Product
Chainlit
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2025-6849

A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknown function of the file /forum_edit1.php. The manipulation of the argument text leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Forum
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-68482

A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack

PUBLISHED
Vendor
Fortinet, Fortinet, Fortinet, Fortinet
Product
FortiAnalyzer Cloud, FortiManager, FortiAnalyzer, FortiManager Cloud
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68481

FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow. `generate_state_token()` is always called with an empty `state_data` dict, so the resulting JWT only contains the fixed audience claim plus an expiration timestamp. On callback, the library merely che

PUBLISHED
Vendor
fastapi-users
Product
fastapi-users
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68480

Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.

PUBLISHED
Vendor
marshmallow-code
Product
marshmallow
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6848

A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Forum
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68479

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack proper checking for ownership before making changes. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known workarounds are available.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
HIGH
Conflicts
0

CVE-2025-68478

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the Flow object into JSON and creates/overwrites a file at that path. There is no path restriction, normalization, or allowed directory enforcement, so absolute paths (e.g., /etc/poc.txt) are interpreted as is. Version 1.7.0 fixes the issue.

PUBLISHED
Vendor
langflow-ai
Product
langflow
Provider severity
HIGH
Conflicts
0

CVE-2025-68477

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides an API Request component that can issue arbitrary HTTP requests within a flow. This component takes a user-supplied URL, performs only normalization and basic format checks, and then sends the request using a server-side httpx client. It does not block private IP ranges (127[.]0[.]0[.]1, the 10/172/192 ranges) or cloud metadata endpoints (169[.]254[.]169[.]254), and it returns

PUBLISHED
Vendor
langflow-ai
Product
langflow
Provider severity
HIGH
Conflicts
0

CVE-2025-68476

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerability stems from an incorrect or insufficient path validation when loading the Service Account Token specified in spec.hashiCorpVault.credential.serviceAccount. An attacker with permissions to create or mo

PUBLISHED
Vendor
kedacore
Product
keda
Provider severity
HIGH
Conflicts
1

CVE-2025-68475

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.

PUBLISHED
Vendor
fedify-dev
Product
fedify
Provider severity
HIGH
Conflicts
0