Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-66135

Missing Authorization vulnerability in merkulove Imager for Elementor imager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Imager for Elementor: from n/a through <= 2.0.4.

PUBLISHED
Vendor
merkulove
Product
Imager for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66134

Missing Authorization vulnerability in NinjaTeam FileBird Pro filebird-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FileBird Pro: from n/a through <= 6.5.1.

PUBLISHED
Vendor
NinjaTeam
Product
FileBird Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66133

Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.7.

PUBLISHED
Vendor
WP Legal Pages
Product
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66132

Authorization Bypass Through User-Controlled Key vulnerability in FAPI Business s.r.o. FAPI Member fapi-member allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FAPI Member: from n/a through <= 2.2.30.

PUBLISHED
Vendor
FAPI Business s.r.o.
Product
FAPI Member
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66131

Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-payment-gateway-for-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yaad Sarig Payment Gateway For WC: from n/a through <= 2.2.11.

PUBLISHED
Vendor
yaadsarig
Product
Yaad Sarig Payment Gateway For WC
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66130

Missing Authorization vulnerability in etruel WP Views Counter wpecounter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Views Counter: from n/a through <= 2.1.2.

PUBLISHED
Vendor
etruel
Product
WP Views Counter
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6613

A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulnerability is an unknown functionality of the file /doctor/manage-patient.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Hospital Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-66129

Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pochipp: from n/a through <= 1.18.0.

PUBLISHED
Vendor
wppochipp
Product
Pochipp
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66128

Missing Authorization vulnerability in Brevo Sendinblue for WooCommerce woocommerce-sendinblue-newsletter-subscription allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sendinblue for WooCommerce: from n/a through <= 4.0.49.

PUBLISHED
Vendor
Brevo
Product
Sendinblue for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66127

Missing Authorization vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Real Estate: from n/a through <= 5.3.2.

PUBLISHED
Vendor
g5theme
Product
Essential Real Estate
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66126

Insertion of Sensitive Information Into Sent Data vulnerability in wowpress.host Fix Media Library wow-media-library-fix allows Retrieve Embedded Sensitive Data.This issue affects Fix Media Library: from n/a through <= 2.0.

PUBLISHED
Vendor
wowpress.host
Product
Fix Media Library
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66125

Insertion of Sensitive Information Into Sent Data vulnerability in Nitesh Ultimate Auction ultimate-auction allows Retrieve Embedded Sensitive Data.This issue affects Ultimate Auction : from n/a through <= 4.3.3.

PUBLISHED
Vendor
Nitesh
Product
Ultimate Auction
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66124

Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leaky Paywall: from n/a through <= 4.22.6.

PUBLISHED
Vendor
ZEEN101
Product
Leaky Paywall
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66123

Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

PUBLISHED
Vendor
About Envato
Product
BookPro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66122

Missing Authorization vulnerability in Design Stylish Price List stylish-price-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stylish Price List: from n/a through <= 7.2.2.

PUBLISHED
Vendor
Design
Product
Stylish Price List
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66121

Missing Authorization vulnerability in SiteGround SiteGround Security sg-security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteGround Security: from n/a through <= 1.5.8.

PUBLISHED
Vendor
SiteGround
Product
SiteGround Security
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66120

Missing Authorization vulnerability in CatFolders CatFolders catfolders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CatFolders: from n/a through <= 2.5.3.

PUBLISHED
Vendor
CatFolders
Product
CatFolders
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6612

A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /php_action/removeCategories.php. The manipulation of the argument categoriesId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Inventory Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-66119

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5.9.

PUBLISHED
Vendor
Bob
Product
Hostel
Provider severity
HIGH
Conflicts
0

CVE-2025-66118

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Reflected XSS.This issue affects Sprout Clients: from n/a through <= 3.2.1.

PUBLISHED
Vendor
BoldGrid
Product
Sprout Clients
Provider severity
HIGH
Conflicts
0

CVE-2025-66117

Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form: from n/a through <= 2.7.8.

PUBLISHED
Vendor
Ays Pro
Product
Easy Form
Provider severity
HIGH
Conflicts
0

CVE-2025-66116

Insertion of Sensitive Information Into Sent Data vulnerability in UserElements Ultimate Member Widgets for Elementor ultimate-member-widgets-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Ultimate Member Widgets for Elementor: from n/a through <= 2.3.

PUBLISHED
Vendor
UserElements
Product
Ultimate Member Widgets for Elementor
Provider severity
HIGH
Conflicts
0

CVE-2025-66115

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4.

PUBLISHED
Vendor
MatrixAddons
Product
Easy Invoice
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66114

Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variations-shop-category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Show Variations as Single Products Woocommerce: from n/a through <= 2.0.

PUBLISHED
Vendor
theme funda
Product
Show Variations as Single Products Woocommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66113

Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Chat Support for Messenger: from n/a through <= 1.2.18.

PUBLISHED
Vendor
ThemeAtelier
Product
Better Chat Support for Messenger
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66112

Missing Authorization vulnerability in WebToffee Accessibility Toolkit by WebYes accessibility-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Toolkit by WebYes: from n/a through <= 2.0.4.

PUBLISHED
Vendor
WebToffee
Product
Accessibility Toolkit by WebYes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66111

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nelio Software Nelio Popups nelio-popups allows Stored XSS.This issue affects Nelio Popups: from n/a through <= 1.3.0.

PUBLISHED
Vendor
Nelio Software
Product
Nelio Popups
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66110

Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tiktok Feed: from n/a through <= 1.0.23.

PUBLISHED
Vendor
bPlugins
Product
Tiktok Feed
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6611

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/createBrand.php. The manipulation of the argument brandStatus leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Inventory Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-66109

Missing Authorization vulnerability in Octolize Shipping Plugins Cart Weight for WooCommerce woo-cart-weight allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cart Weight for WooCommerce: from n/a through <= 1.9.11.

PUBLISHED
Vendor
Octolize Shipping Plugins
Product
Cart Weight for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66108

Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4.

PUBLISHED
Vendor
Merlot Digital (by TNC)
Product
TNC Toolbox: Web Performance
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66107

Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7.

PUBLISHED
Vendor
Scott Paterson
Product
Subscriptions & Memberships for PayPal
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66106

Missing Authorization vulnerability in Essential Plugin Featured Post Creative featured-post-creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through <= 1.5.5.

PUBLISHED
Vendor
Essential Plugin
Product
Featured Post Creative
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66105

Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8.

PUBLISHED
Vendor
Magepeople inc.
Product
Bus Ticket Booking with Seat Reservation
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66104

Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Offload, AI & Optimize with Cloudflare Images: from n/a through <= 1.9.5.

PUBLISHED
Vendor
Anton Vanyukov
Product
Offload, AI & Optimize with Cloudflare Images
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66103

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx WPCal.io wpcal allows DOM-Based XSS.This issue affects WPCal.io: from n/a through <= 0.9.5.9.

PUBLISHED
Vendor
revmakx
Product
WPCal.io
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66102

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7.

PUBLISHED
Vendor
FolioVision
Product
FV Antispam
Provider severity
HIGH
Conflicts
0

CVE-2025-66101

Missing Authorization vulnerability in Sabuj Kundu CBX Bookmark & Favorite cbxwpbookmark allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CBX Bookmark & Favorite: from n/a through <= 2.0.1.

PUBLISHED
Vendor
Sabuj Kundu
Product
CBX Bookmark & Favorite
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66100

Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.3.5.

PUBLISHED
Vendor
Magnigenie
Product
RestroPress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6610

A vulnerability was found in itsourcecode Employee Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file /admin/editempprofile.php. The manipulation of the argument FirstName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Employee Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-66099

Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chat Help: from n/a through <= 3.1.3.

PUBLISHED
Vendor
ThemeAtelier
Product
Chat Help
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66098

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille V Travelers' Map travelers-map allows Stored XSS.This issue affects Travelers' Map: from n/a through <= 2.3.2.

PUBLISHED
Vendor
Camille V
Product
Travelers' Map
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66097

Cross-Site Request Forgery (CSRF) vulnerability in Igor Jerosimić I Order Terms i-order-terms allows Cross Site Request Forgery.This issue affects I Order Terms: from n/a through <= 1.5.0.

PUBLISHED
Vendor
Igor Jerosimić
Product
I Order Terms
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66096

Missing Authorization vulnerability in Imtiaz Rayhan Table Block by Tableberg tableberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Table Block by Tableberg: from n/a through <= 0.6.9.

PUBLISHED
Vendor
Imtiaz Rayhan
Product
Table Block by Tableberg
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66095

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13.

PUBLISHED
Vendor
Iqonic Design
Product
KiviCare
Provider severity
HIGH
Conflicts
0

CVE-2025-66094

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dmccan Yada Wiki yada-wiki allows Stored XSS.This issue affects Yada Wiki: from n/a through <= 3.5.

PUBLISHED
Vendor
dmccan
Product
Yada Wiki
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66093

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through <= 4.8.

PUBLISHED
Vendor
hupe13
Product
Extensions for Leaflet Map
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66092

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bqworks Accordion Slider accordion-slider allows Stored XSS.This issue affects Accordion Slider: from n/a through <= 1.9.13.

PUBLISHED
Vendor
bqworks
Product
Accordion Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66091

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Design Stylish Cost Calculator stylish-cost-calculator allows DOM-Based XSS.This issue affects Stylish Cost Calculator: from n/a through <= 8.1.5.

PUBLISHED
Vendor
Design
Product
Stylish Cost Calculator
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66090

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Skill Bar skt-skill-bar allows DOM-Based XSS.This issue affects SKT Skill Bar: from n/a through <= 2.5.

PUBLISHED
Vendor
sonalsinha21
Product
SKT Skill Bar
Provider severity
MEDIUM
Conflicts
0