Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-64231

Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contact Form 7 PDF, Google Sheet & Database: from n/a through <= 3.0.0.

PUBLISHED
Vendor
RedefiningTheWeb
Product
WordPress Contact Form 7 PDF, Google Sheet & Database
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64230

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Chill Filr filr-protection allows Path Traversal.This issue affects Filr: from n/a through <= 1.2.10.

PUBLISHED
Vendor
WP Chill
Product
Filr
Provider severity
HIGH
Conflicts
0

CVE-2025-6423

The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_submit_upload_file() function in all versions up to, and including, 2.3.5. This makes it possible for authenticated attackers with Subscriber-level access or higher to upload arbitrary files on the affected site's server which may make remote code execution possible.

PUBLISHED
Vendor
beeteam368
Product
BeeTeam368 Extensions
Provider severity
HIGH
Conflicts
0

CVE-2025-64229

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.

PUBLISHED
Vendor
BoldGrid
Product
Client Invoicing by Sprout Invoices
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64228

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Retrieve Embedded Sensitive Data.This issue affects SUMO Affiliates Pro: from n/a through <= 11.0.0.

PUBLISHED
Vendor
FantasticPlugins
Product
SUMO Affiliates Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64227

Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.

PUBLISHED
Vendor
BoldGrid
Product
Client Invoicing by Sprout Invoices
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64226

Cross-Site Request Forgery (CSRF) vulnerability in colabrio Stockie Extra stockie-extra allows Cross Site Request Forgery.This issue affects Stockie Extra: from n/a through <= 1.2.11.

PUBLISHED
Vendor
colabrio
Product
Stockie Extra
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64225

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Stockie Extra stockie-extra allows Code Injection.This issue affects Stockie Extra: from n/a through <= 1.2.11.

PUBLISHED
Vendor
colabrio
Product
Stockie Extra
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64224

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Reflected XSS.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Conference Theme Custom Post Type
Provider severity
HIGH
Conflicts
0

CVE-2025-64223

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign PenNews pennews allows PHP Local File Inclusion.This issue affects PenNews: from n/a through < 6.7.3.

PUBLISHED
Vendor
PenciDesign
Product
PenNews
Provider severity
HIGH
Conflicts
0

CVE-2025-64222

Missing Authorization vulnerability in FantasticPlugins WooCommerce Recover Abandoned Cart rac allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Recover Abandoned Cart: from n/a through <= 24.6.0.

PUBLISHED
Vendor
FantasticPlugins
Product
WooCommerce Recover Abandoned Cart
Provider severity
HIGH
Conflicts
0

CVE-2025-64221

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Reflected XSS.This issue affects Reservation Plugin: from n/a through <= 1.6.

PUBLISHED
Vendor
designthemes
Product
Reservation Plugin
Provider severity
HIGH
Conflicts
0

CVE-2025-64220

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReyCommerce Rey Core rey-core allows Stored XSS.This issue affects Rey Core: from n/a through <= 3.1.8.

PUBLISHED
Vendor
ReyCommerce
Product
Rey Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6422

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=save_settings of the component About Content Page. The manipulation of the argument img leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Campcodes
Product
Online Recruitment Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-64219

Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.18.

PUBLISHED
Vendor
Strategy11 Team
Product
Business Directory
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64218

Insertion of Sensitive Information Into Sent Data vulnerability in WP Chill Passster content-protector allows Retrieve Embedded Sensitive Data.This issue affects Passster: from n/a through <= 4.2.19.

PUBLISHED
Vendor
WP Chill
Product
Passster
Provider severity
HIGH
Conflicts
0

CVE-2025-64217

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows Reflected XSS.This issue affects Photography: from n/a through <= 7.7.2.

PUBLISHED
Vendor
ThemeGoods
Product
Photography
Provider severity
HIGH
Conflicts
0

CVE-2025-64216

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeSphere SmartMag smart-mag allows PHP Local File Inclusion.This issue affects SmartMag: from n/a through <= 10.3.0.

PUBLISHED
Vendor
ThemeSphere
Product
SmartMag
Provider severity
HIGH
Conflicts
0

CVE-2025-64215

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.

PUBLISHED
Vendor
StylemixThemes
Product
MasterStudy LMS Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64214

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.

PUBLISHED
Vendor
StylemixThemes
Product
MasterStudy LMS Pro
Provider severity
HIGH
Conflicts
0

CVE-2025-64213

Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.

PUBLISHED
Vendor
StylemixThemes
Product
MasterStudy LMS Pro
Provider severity
HIGH
Conflicts
0

CVE-2025-64212

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.

PUBLISHED
Vendor
StylemixThemes
Product
MasterStudy LMS Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64211

Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy Elementor Widgets: from n/a through <= 1.2.4.

PUBLISHED
Vendor
StylemixThemes
Product
Masterstudy Elementor Widgets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64210

Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Masterstudy Elementor Widgets: from n/a through <= 1.2.4.

PUBLISHED
Vendor
StylemixThemes
Product
Masterstudy Elementor Widgets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6421

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/add_account.php. The manipulation of the argument name/admin_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Online Hotel Reservation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-64209

Missing Authorization vulnerability in StylemixThemes Masterstudy masterstudy allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy: from n/a through < 4.8.122.

PUBLISHED
Vendor
StylemixThemes
Product
Masterstudy
Provider severity
HIGH
Conflicts
0

CVE-2025-64208

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Jannah - Extensions jannah-extensions allows DOM-Based XSS.This issue affects Jannah - Extensions: from n/a through <= 1.1.4.

PUBLISHED
Vendor
TieLabs
Product
Jannah - Extensions
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64207

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Jannah jannah allows DOM-Based XSS.This issue affects Jannah: from n/a through <= 7.6.0.

PUBLISHED
Vendor
TieLabs
Product
Jannah
Provider severity
HIGH
Conflicts
0

CVE-2025-64206

Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0.

PUBLISHED
Vendor
TieLabs
Product
Jannah
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64205

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.0.

PUBLISHED
Vendor
TieLabs
Product
Jannah
Provider severity
HIGH
Conflicts
0

CVE-2025-64204

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeSphere SmartMag smart-mag allows Stored XSS.This issue affects SmartMag: from n/a through <= 10.3.1.

PUBLISHED
Vendor
ThemeSphere
Product
SmartMag
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64203

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster mailster allows Reflected XSS.This issue affects Mailster: from n/a through < 4.1.14.

PUBLISHED
Vendor
EverPress
Product
Mailster
Provider severity
HIGH
Conflicts
0

CVE-2025-64202

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Sahifa sahifa allows DOM-Based XSS.This issue affects Sahifa: from n/a through < 5.8.6.

PUBLISHED
Vendor
TieLabs
Product
Sahifa
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64201

Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12.

PUBLISHED
Vendor
blubrry
Product
PowerPress Podcasting
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64200

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Email Template Customizer for WooCommerce email-template-customizer-for-woo allows Stored XSS.This issue affects Email Template Customizer for WooCommerce: from n/a through <= 1.2.17.

PUBLISHED
Vendor
VillaTheme
Product
Email Template Customizer for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6420

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add_room.php. The manipulation of the argument room_type leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Online Hotel Reservation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-64199

Missing Authorization vulnerability in WpEstate wpresidence wpresidence allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpresidence: from n/a through <= 5.3.2.

PUBLISHED
Vendor
WpEstate
Product
wpresidence
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64198

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Easy Social Share Buttons easy-social-share-buttons3 allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through < 10.7.1.

PUBLISHED
Vendor
appscreo
Product
Easy Social Share Buttons
Provider severity
HIGH
Conflicts
0

CVE-2025-64197

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam Rehub rehub-theme allows Stored XSS.This issue affects Rehub: from n/a through < 19.9.9.1.

PUBLISHED
Vendor
sizam
Product
Rehub
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64196

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Reflected XSS.This issue affects Booster for WooCommerce: from n/a through <= 7.2.5.

PUBLISHED
Vendor
Pluggabl
Product
Booster for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-64195

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Eduma eduma allows PHP Local File Inclusion.This issue affects Eduma: from n/a through <= 5.7.6.

PUBLISHED
Vendor
ThimPress
Product
Eduma
Provider severity
HIGH
Conflicts
0

CVE-2025-64194

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma eduma allows Stored XSS.This issue affects Eduma: from n/a through <= 5.7.6.

PUBLISHED
Vendor
ThimPress
Product
Eduma
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64193

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in 8theme XStore xstore allows PHP Local File Inclusion.This issue affects XStore: from n/a through < 9.6.1.

PUBLISHED
Vendor
8theme
Product
XStore
Provider severity
HIGH
Conflicts
0

CVE-2025-64192

Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects XStore: from n/a through < 9.6.

PUBLISHED
Vendor
8theme
Product
XStore
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64191

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows Reflected XSS.This issue affects XStore: from n/a through < 9.6.1.

PUBLISHED
Vendor
8theme
Product
XStore
Provider severity
HIGH
Conflicts
0

CVE-2025-64190

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.6.

PUBLISHED
Vendor
8theme
Product
XStore Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6419

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit_room.php. The manipulation of the argument room_type leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Online Hotel Reservation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-64189

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through < 5.6.

PUBLISHED
Vendor
8theme
Product
XStore Core
Provider severity
HIGH
Conflicts
0

CVE-2025-64188

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.

PUBLISHED
Vendor
PenciDesign
Product
Soledad
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64187

OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Action Command notifications and prompts popups generated by the printer. An attacker who successfully convinces a victim to print a specially crafted file could exploit this issue to disrupt ongoing prints, extract information (including sensitive configuration settings, if the targeted user has the necessa

PUBLISHED
Vendor
OctoPrint
Product
OctoPrint
Provider severity
MEDIUM
Conflicts
0