Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-68083

Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cross Site Request Forgery.This issue affects Meks Quick Plugin Disabler: from n/a through <= 1.0.

PUBLISHED
Vendor
Meks
Product
Meks Quick Plugin Disabler
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68082

Cross-Site Request Forgery (CSRF) vulnerability in SEMrush CY LTD Semrush Content Toolkit semrush-contentshake allows Cross Site Request Forgery.This issue affects Semrush Content Toolkit: from n/a through <= 1.1.32.

PUBLISHED
Vendor
SEMrush CY LTD
Product
Semrush Content Toolkit
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68081

Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

PUBLISHED
Vendor
Lester Chan
Product
WP-Polls
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68080

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal User Avatar - Reloaded user-avatar-reloaded allows Stored XSS.This issue affects User Avatar - Reloaded: from n/a through <= 1.2.2.

PUBLISHED
Vendor
Saad Iqbal
Product
User Avatar - Reloaded
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68079

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salient Shortcodes salient-shortcodes allows Stored XSS.This issue affects Salient Shortcodes: from n/a through <= 1.5.4.

PUBLISHED
Vendor
ThemeNectar
Product
Salient Shortcodes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68078

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salient Portfolio salient-portfolio allows Stored XSS.This issue affects Salient Portfolio: from n/a through <= 1.8.2.

PUBLISHED
Vendor
ThemeNectar
Product
Salient Portfolio
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68077

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm stockholm allows Stored XSS.This issue affects Stockholm: from n/a through <= 9.14.1.

PUBLISHED
Vendor
Select-Themes
Product
Stockholm
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68076

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core stockholm-core allows Stored XSS.This issue affects Stockholm Core: from n/a through <= 2.4.6.

PUBLISHED
Vendor
Select-Themes
Product
Stockholm Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68075

Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

PUBLISHED
Vendor
Kerry
Product
BNE Testimonials
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68074

Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

PUBLISHED
Vendor
GhozyLab
Product
Image Carousel
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68073

Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.4.

PUBLISHED
Vendor
Ninja Team
Product
GDPR CCPA Compliance Support
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68072

Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.20.

PUBLISHED
Vendor
Merv Barrett
Product
Easy Property Listings
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68071

Authorization Bypass Through User-Controlled Key vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Real Estate: from n/a through <= 5.3.2.

PUBLISHED
Vendor
g5theme
Product
Essential Real Estate
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68070

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vektor,Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Stored XSS.This issue affects VK Google Job Posting Manager: from n/a through <= 1.2.22.

PUBLISHED
Vendor
Vektor,Inc.
Product
VK Google Job Posting Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6807

Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the getDriverTmpPath method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An atta

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68069

Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.6.6.

PUBLISHED
Vendor
wpWax
Product
Directorist
Provider severity
HIGH
Conflicts
0

CVE-2025-68068

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm stockholm allows PHP Local File Inclusion.This issue affects Stockholm: from n/a through <= 9.14.1.

PUBLISHED
Vendor
Select-Themes
Product
Stockholm
Provider severity
HIGH
Conflicts
0

CVE-2025-68067

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm Core stockholm-core allows PHP Local File Inclusion.This issue affects Stockholm Core: from n/a through <= 2.4.6.

PUBLISHED
Vendor
Select-Themes
Product
Stockholm Core
Provider severity
HIGH
Conflicts
0

CVE-2025-68066

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion.This issue affects Soledad: from n/a through <= 8.7.0.

PUBLISHED
Vendor
PenciDesign
Product
Soledad
Provider severity
HIGH
Conflicts
0

CVE-2025-68065

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LiquidThemes Hub Core allows PHP Local File Inclusion. This issue affects Hub Core: from n/a before 6.0.2.

PUBLISHED
Vendor
LiquidThemes
Product
Hub Core
Provider severity
HIGH
Conflicts
0

CVE-2025-68064

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

PUBLISHED
Vendor
Everthemess
Product
Goya Core
Provider severity
HIGH
Conflicts
0

CVE-2025-68063

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

PUBLISHED
Vendor
StylemixThemes
Product
Splash - Sport Club WordPress Theme for Basketball, Football, Hockey
Provider severity
HIGH
Conflicts
0

CVE-2025-68062

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6.

PUBLISHED
Vendor
ThemeMove
Product
MinimogWP
Provider severity
HIGH
Conflicts
0

CVE-2025-68061

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall allows PHP Local File Inclusion.This issue affects EduMall: from n/a through <= 4.4.7.

PUBLISHED
Vendor
ThemeMove
Product
EduMall
Provider severity
HIGH
Conflicts
0

CVE-2025-68060

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allows Blind SQL Injection. This issue affects Team Member: from n/a through 8.5.

PUBLISHED
Vendor
WPMart
Product
Team Member
Provider severity
HIGH
Conflicts
0

CVE-2025-6806

Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the decryptFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage th

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-68059

Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Listing: from n/a through <= 1.4.2.

PUBLISHED
Vendor
e-plugins
Product
Hotel Listing
Provider severity
HIGH
Conflicts
0

CVE-2025-68058

Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3..4.

PUBLISHED
Vendor
e-plugins
Product
Institutions Directory
Provider severity
HIGH
Conflicts
0

CVE-2025-68057

Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hospital Doctor Directory: from n/a through <= 1.3.9.

PUBLISHED
Vendor
e-plugins
Product
Hospital Doctor Directory
Provider severity
HIGH
Conflicts
0

CVE-2025-68056

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutslider allows SQL Injection.This issue affects LBG Zoominoutslider: from n/a through <= 5.4.4.

PUBLISHED
Vendor
LambertGroup
Product
LBG Zoominoutslider
Provider severity
HIGH
Conflicts
0

CVE-2025-68055

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.32.

PUBLISHED
Vendor
Themefic
Product
Hydra Booking
Provider severity
HIGH
Conflicts
0

CVE-2025-68054

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown With Image or Video Background countdown_with_background allows Blind SQL Injection.This issue affects CountDown With Image or Video Background: from n/a through <= 1.5.

PUBLISHED
Vendor
LambertGroup
Product
CountDown With Image or Video Background
Provider severity
HIGH
Conflicts
0

CVE-2025-68053

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows Blind SQL Injection.This issue affects xPromoter: from n/a through <= 1.3.4.

PUBLISHED
Vendor
LambertGroup
Product
xPromoter
Provider severity
HIGH
Conflicts
0

CVE-2025-68052

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

PUBLISHED
Vendor
Eagle-Themes
Product
Eagle Booking
Provider severity
HIGH
Conflicts
0

CVE-2025-68051

Authorization Bypass Through User-Controlled Key vulnerability in Shiprocket Shiprocket shiprocket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shiprocket: from n/a through <= 2.0.8.

PUBLISHED
Vendor
Shiprocket
Product
Shiprocket
Provider severity
HIGH
Conflicts
0

CVE-2025-68050

Missing Authorization vulnerability in Leadpages Leadpages leadpages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leadpages: from n/a through <= 1.1.3.

PUBLISHED
Vendor
Leadpages
Product
Leadpages
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6805

Marvell QConvergeConsole deleteEventLogFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the deleteEventLogFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacke

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-68049

Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.

PUBLISHED
Vendor
bunny.net
Product
bunny.net
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68048

Missing Authorization vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0.

PUBLISHED
Vendor
XLPlugins
Product
NextMove Lite
Provider severity
HIGH
Conflicts
0

CVE-2025-68047

Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.3.

PUBLISHED
Vendor
Arraytics
Product
Eventin
Provider severity
HIGH
Conflicts
0

CVE-2025-68046

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Retrieve Embedded Sensitive Data.This issue affects Contact Form & Lead Form Elementor Builder: from n/a through <= 2.0.1.

PUBLISHED
Vendor
ThemeHunk
Product
Contact Form & Lead Form Elementor Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68045

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

PUBLISHED
Vendor
Arraytics
Product
WP Event SOlution
Provider severity
HIGH
Conflicts
0

CVE-2025-68044

Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.4.

PUBLISHED
Vendor
Rustaurius
Product
Five Star Restaurant Reservations
Provider severity
HIGH
Conflicts
0

CVE-2025-68043

Missing Authorization vulnerability in LottieFiles LottieFiles lottiefiles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LottieFiles: from n/a through <= 3.0.0.

PUBLISHED
Vendor
LottieFiles
Product
LottieFiles
Provider severity
HIGH
Conflicts
0

CVE-2025-68042

Missing Authorization vulnerability in Travelpayouts Travelpayouts travelpayouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelpayouts: from n/a through <= 1.2.2.

PUBLISHED
Vendor
Travelpayouts
Product
Travelpayouts
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68041

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codisto Omnichannel for WooCommerce codistoconnect allows Stored XSS.This issue affects Omnichannel for WooCommerce: from n/a through <= 1.3.65.

PUBLISHED
Vendor
codisto
Product
Omnichannel for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-68040

Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 3.0.1.

PUBLISHED
Vendor
weDevs
Product
WP Project Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6804

Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the compressFirmwareDumpFiles method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file o

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-68039

Missing Authorization vulnerability in Chris Simmons WP BackItUp wp-backitup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP BackItUp: from n/a through <= 2.1.0.

PUBLISHED
Vendor
Chris Simmons
Product
WP BackItUp
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68038

Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Icegram Express Pro: from n/a through < 5.9.14.

PUBLISHED
Vendor
Icegram
Product
Icegram Express Pro
Provider severity
HIGH
Conflicts
0