Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-67991

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Reflected XSS.This issue affects User Extra Fields: from n/a through <= 16.8.

PUBLISHED
Vendor
vanquish
Product
User Extra Fields
Provider severity
HIGH
Conflicts
0

CVE-2025-67990

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 GMap Targeting gmap-targeting allows Reflected XSS.This issue affects GMap Targeting: from n/a through <= 1.1.7.

PUBLISHED
Vendor
RealMag777
Product
GMap Targeting
Provider severity
HIGH
Conflicts
0

CVE-2025-6799

Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the getFileUploadBytes method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-67989

Server-Side Request Forgery (SSRF) vulnerability in LMPixels Kerge kerge allows Server Side Request Forgery.This issue affects Kerge: from n/a through <= 4.1.3.

PUBLISHED
Vendor
LMPixels
Product
Kerge
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67988

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean CozyStay cozystay allows PHP Local File Inclusion.This issue affects CozyStay: from n/a through < 1.9.1.

PUBLISHED
Vendor
LoftOcean
Product
CozyStay
Provider severity
HIGH
Conflicts
0

CVE-2025-67987

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1.

PUBLISHED
Vendor
ExpressTech Systems
Product
Quiz And Survey Master
Provider severity
HIGH
Conflicts
0

CVE-2025-67986

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows DOM-Based XSS.This issue affects Document Library Lite: from n/a through <= 1.1.7.

PUBLISHED
Vendor
Barn2 Plugins
Product
Document Library Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67985

Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Document Library Lite: from n/a through <= 1.1.7.

PUBLISHED
Vendor
Barn2 Plugins
Product
Document Library Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67984

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in calliko NPS computy nps-computy allows DOM-Based XSS.This issue affects NPS computy: from n/a through <= 2.8.2.

PUBLISHED
Vendor
calliko
Product
NPS computy
Provider severity
HIGH
Conflicts
0

CVE-2025-67983

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows DOM-Based XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.3.

PUBLISHED
Vendor
osama.esh
Product
WP Visitor Statistics (Real Time Traffic)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67982

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This issue affects Urna: from n/a through <= 2.5.12.

PUBLISHED
Vendor
thembay
Product
Urna
Provider severity
HIGH
Conflicts
0

CVE-2025-67981

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This issue affects Besa: from n/a through <= 2.3.15.

PUBLISHED
Vendor
thembay
Product
Besa
Provider severity
HIGH
Conflicts
0

CVE-2025-67980

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara hara allows PHP Local File Inclusion.This issue affects Hara: from n/a through <= 1.2.17.

PUBLISHED
Vendor
thembay
Product
Hara
Provider severity
HIGH
Conflicts
0

CVE-2025-6798

Marvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the deleteAppFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leve

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-67979

Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows Code Injection.This issue affects WPForms Google Sheet Connector: from n/a through <= 4.0.1.

PUBLISHED
Vendor
WesternDeal
Product
WPForms Google Sheet Connector
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67978

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FixBD Educare educare allows Reflected XSS.This issue affects Educare: from n/a through <= 1.6.1.

PUBLISHED
Vendor
FixBD
Product
Educare
Provider severity
HIGH
Conflicts
0

CVE-2025-67977

Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.8.

PUBLISHED
Vendor
VillaTheme
Product
HAPPY
Provider severity
HIGH
Conflicts
0

CVE-2025-67976

Missing Authorization vulnerability in Bob Watu Quiz watu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watu Quiz: from n/a through <= 3.4.5.

PUBLISHED
Vendor
Bob
Product
Watu Quiz
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67975

Missing Authorization vulnerability in aDirectory aDirectory adirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects aDirectory: from n/a through <= 3.0.3.

PUBLISHED
Vendor
aDirectory
Product
aDirectory
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67974

Missing Authorization vulnerability in WP Legal Pages WPLegalPages wplegalpages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLegalPages: from n/a through <= 3.5.4.

PUBLISHED
Vendor
WP Legal Pages
Product
WPLegalPages
Provider severity
HIGH
Conflicts
0

CVE-2025-67973

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2.

PUBLISHED
Vendor
sunshinephotocart
Product
Sunshine Photo Cart
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67972

Missing Authorization vulnerability in Zoho Mail Zoho ZeptoMail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zoho ZeptoMail: from n/a through 3.2.9.

PUBLISHED
Vendor
Zoho Mail
Product
Zoho ZeptoMail
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67971

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja FluentCart fluent-cart allows Reflected XSS.This issue affects FluentCart: from n/a through < 1.3.0.

PUBLISHED
Vendor
WPManageNinja
Product
FluentCart
Provider severity
HIGH
Conflicts
0

CVE-2025-67970

Missing Authorization vulnerability in vertim Schedula schedula-smart-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schedula: from n/a through <= 1.0.

PUBLISHED
Vendor
vertim
Product
Schedula
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6797

Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the getFileUploadBytes method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-67969

Missing Authorization vulnerability in knitpay UPI QR Code Payment Gateway for WooCommerce upi-qr-code-payment-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPI QR Code Payment Gateway for WooCommerce: from n/a through <= 1.5.1.

PUBLISHED
Vendor
knitpay
Product
UPI QR Code Payment Gateway for WooCommerce
Provider severity
MEDIUM
Conflicts
1

CVE-2025-67968

Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue affects Real Homes CRM: from n/a through <= 1.0.0.

PUBLISHED
Vendor
InspiryThemes
Product
Real Homes CRM
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67967

Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lawyer Directory: from n/a through <= 1.3.3.

PUBLISHED
Vendor
e-plugins
Product
Lawyer Directory
Provider severity
HIGH
Conflicts
0

CVE-2025-67966

Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.This issue affects Lawyer Directory: from n/a through <= 1.3.3.

PUBLISHED
Vendor
e-plugins
Product
Lawyer Directory
Provider severity
HIGH
Conflicts
0

CVE-2025-67965

Missing Authorization vulnerability in favethemes Homey Core homey-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Homey Core: from n/a through <= 2.4.3.

PUBLISHED
Vendor
favethemes
Product
Homey Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67964

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey Core homey-core allows Reflected XSS.This issue affects Homey Core: from n/a through <= 2.4.3.

PUBLISHED
Vendor
favethemes
Product
Homey Core
Provider severity
HIGH
Conflicts
0

CVE-2025-67963

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ovatheme Movie Booking movie-booking allows Path Traversal.This issue affects Movie Booking: from n/a through <= 1.1.5.

PUBLISHED
Vendor
ovatheme
Product
Movie Booking
Provider severity
HIGH
Conflicts
0

CVE-2025-67962

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AIOSEO Plugin Team Broken Link Checker broken-link-checker-seo allows SQL Injection.This issue affects Broken Link Checker: from n/a through <= 1.2.6.

PUBLISHED
Vendor
AIOSEO Plugin Team
Product
Broken Link Checker
Provider severity
HIGH
Conflicts
0

CVE-2025-67961

Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365: from n/a through <= 40.0.

PUBLISHED
Vendor
Marco van Wieren
Product
WPO365
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67960

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout-Core workscout-core allows Reflected XSS.This issue affects WorkScout-Core: from n/a through <= 1.7.06.

PUBLISHED
Vendor
purethemes
Product
WorkScout-Core
Provider severity
HIGH
Conflicts
0

CVE-2025-6796

Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the getAppFileBytes method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attack

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
HIGH
Conflicts
0

CVE-2025-67959

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout workscout allows Reflected XSS.This issue affects WorkScout: from n/a through <= 4.1.07.

PUBLISHED
Vendor
purethemes
Product
WorkScout
Provider severity
HIGH
Conflicts
0

CVE-2025-67958

Missing Authorization vulnerability in Taxcloud TaxCloud for WooCommerce simple-sales-tax allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TaxCloud for WooCommerce: from n/a through <= 8.3.8.

PUBLISHED
Vendor
Taxcloud
Product
TaxCloud for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67957

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP Listivo Core listivo-core allows PHP Local File Inclusion.This issue affects Listivo Core: from n/a through <= 2.3.77.

PUBLISHED
Vendor
TangibleWP
Product
Listivo Core
Provider severity
HIGH
Conflicts
0

CVE-2025-67956

Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.6.

PUBLISHED
Vendor
wpeverest
Product
User Registration
Provider severity
HIGH
Conflicts
1

CVE-2025-67955

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP MyHome Core myhome-core allows PHP Local File Inclusion.This issue affects MyHome Core: from n/a through <= 4.1.0.

PUBLISHED
Vendor
TangibleWP
Product
MyHome Core
Provider severity
HIGH
Conflicts
0

CVE-2025-67954

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3.

PUBLISHED
Vendor
Dimitri Grassi
Product
Salon booking system
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67953

Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Booking Activities: from n/a through <= 1.16.44.

PUBLISHED
Vendor
Booking Activities Team
Product
Booking Activities
Provider severity
HIGH
Conflicts
0

CVE-2025-67952

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Tour grandtour allows Reflected XSS.This issue affects Grand Tour: from n/a through < 5.6.2.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Tour
Provider severity
HIGH
Conflicts
0

CVE-2025-67951

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addons for Elementor wpzoom-elementor-addons allows DOM-Based XSS.This issue affects WPZOOM Addons for Elementor: from n/a through <= 1.2.10.

PUBLISHED
Vendor
WPZOOM
Product
WPZOOM Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67950

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack allows Blind SQL Injection.This issue affects All In One SEO Pack: from n/a through <= 4.9.1.

PUBLISHED
Vendor
Syed Balkhi
Product
All In One SEO Pack
Provider severity
HIGH
Conflicts
0

CVE-2025-6795

Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the getFileUploadSize method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An at

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67949

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko hostiko allows Reflected XSS.This issue affects Hostiko: from n/a through < 94.3.6.

PUBLISHED
Vendor
designingmedia
Product
Hostiko
Provider severity
HIGH
Conflicts
0

CVE-2025-67948

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Retrieve Embedded Sensitive Data.This issue affects SendPulse Email Marketing Newsletter: from n/a through <= 2.2.1.

PUBLISHED
Vendor
SendPulse
Product
SendPulse Email Marketing Newsletter
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67947

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle AdForest Elementor adforest-elementor allows Reflected XSS.This issue affects AdForest Elementor: from n/a through <= 3.0.11.

PUBLISHED
Vendor
scriptsbundle
Product
AdForest Elementor
Provider severity
HIGH
Conflicts
0