Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-6308

A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/bwdates-request-report-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Emergency Ambulance Hiring Portal
Provider severity
MEDIUM
Conflicts
2

CVE-2025-63079

Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.

PUBLISHED
Vendor
bdthemes
Product
Live Copy Paste for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63078

Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.

PUBLISHED
Vendor
jetmonsters
Product
Restaurant Menu by MotoPress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63077

Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n/a through <= 3.20.3.

PUBLISHED
Vendor
HappyMonster
Product
Happy Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63076

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 Elements dt-the7-core allows PHP Local File Inclusion.This issue affects The7 Elements: from n/a through <= 2.7.11.

PUBLISHED
Vendor
Dream-Theme
Product
The7 Elements
Provider severity
HIGH
Conflicts
0

CVE-2025-63075

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in muffingroup Betheme betheme allows DOM-Based XSS.This issue affects Betheme: from n/a through <= 28.2.

PUBLISHED
Vendor
muffingroup
Product
Betheme
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63074

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 dt-the7 allows PHP Local File Inclusion.This issue affects The7: from n/a through < 12.8.1.1.

PUBLISHED
Vendor
Dream-Theme
Product
The7
Provider severity
HIGH
Conflicts
0

CVE-2025-63073

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dream-Theme The7 dt-the7 allows DOM-Based XSS.This issue affects The7: from n/a through < 12.9.0.

PUBLISHED
Vendor
Dream-Theme
Product
The7
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63072

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in THEMECO Cornerstone cornerstone allows Stored XSS.This issue affects Cornerstone: from n/a through <= 7.7.3.

PUBLISHED
Vendor
THEMECO
Product
Cornerstone
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63071

Insertion of Sensitive Information Into Sent Data vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.15.

PUBLISHED
Vendor
averta
Product
Shortcodes and extra features for Phlox theme
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63070

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.32.

PUBLISHED
Vendor
Shahjada
Product
Download Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6307

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file /function/edit_customer.php. The manipulation of the argument firstname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

PUBLISHED
Vendor
code-projects
Product
Online Shoe Store
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-63069

Missing Authorization vulnerability in Vinod Dalvi Ivory Search add-search-to-menu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ivory Search: from n/a through <= 5.5.12.

PUBLISHED
Vendor
Vinod Dalvi
Product
Ivory Search
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63068

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension allows Code Injection.This issue affects Contact Form 7 – Dynamic Text Extension: from n/a through <= 5.0.5.

PUBLISHED
Vendor
sevenspark
Product
Contact Form 7 – Dynamic Text Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63067

Missing Authorization vulnerability in p-themes Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: from n/a through < 3.7.3.

PUBLISHED
Vendor
p-themes
Product
Porto Theme - Functionality
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63066

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in p-themes Porto Theme - Functionality porto-functionality allows Stored XSS.This issue affects Porto Theme - Functionality: from n/a through < 3.7.3.

PUBLISHED
Vendor
p-themes
Product
Porto Theme - Functionality
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63065

Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media LIbrary Assistant: from n/a through <= 3.29.

PUBLISHED
Vendor
David Lingren
Product
Media LIbrary Assistant
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63064

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ashanjay EventON eventon allows Stored XSS.This issue affects EventON: from n/a through <= 4.9.12.

PUBLISHED
Vendor
ashanjay
Product
EventON
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63063

Missing Authorization vulnerability in Yandex Metrika Yandex.Metrica wp-yandex-metrika allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yandex.Metrica: from n/a through <= 1.2.2.

PUBLISHED
Vendor
Yandex Metrika
Product
Yandex.Metrica
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63062

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AndonDesign UDesign Core u-design-core allows PHP Local File Inclusion.This issue affects UDesign Core: from n/a through <= 4.14.0.

PUBLISHED
Vendor
AndonDesign
Product
UDesign Core
Provider severity
HIGH
Conflicts
0

CVE-2025-63061

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hogash KALLYAS kallyas allows DOM-Based XSS.This issue affects KALLYAS: from n/a through < 4.25.0.

PUBLISHED
Vendor
hogash
Product
KALLYAS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63060

Cross-Site Request Forgery (CSRF) vulnerability in hogash KALLYAS kallyas allows Cross Site Request Forgery.This issue affects KALLYAS: from n/a through < 4.25.0.

PUBLISHED
Vendor
hogash
Product
KALLYAS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6306

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/admin_index.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Shoe Store
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-63059

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arscode Ninja Popups arscode-ninja-popups allows Stored XSS.This issue affects Ninja Popups: from n/a through <= 4.7.8.

PUBLISHED
Vendor
arscode
Product
Ninja Popups
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63058

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Retrieve Embedded Sensitive Data.This issue affects Custom Field Template: from n/a through <= 2.7.6.

PUBLISHED
Vendor
Hiroaki Miyashita
Product
Custom Field Template
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63057

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows DOM-Based XSS.This issue affects Wp Ultimate Review: from n/a through <= 2.3.7.

PUBLISHED
Vendor
Roxnor
Product
Wp Ultimate Review
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63056

Missing Authorization vulnerability in bestwebsoft Contact Form by BestWebSoft contact-form-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by BestWebSoft: from n/a through <= 4.3.6.

PUBLISHED
Vendor
bestwebsoft
Product
Contact Form by BestWebSoft
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63055

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through <= 2.0.9.9.4.

PUBLISHED
Vendor
Liton Arefin
Product
Master Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63054

Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.2.

PUBLISHED
Vendor
ExpressTech Systems
Product
Quiz And Survey Master
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63053

Authorization Bypass Through User-Controlled Key vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Master Addons for Elementor: from n/a through <= 2.0.9.9.4.

PUBLISHED
Vendor
Liton Arefin
Product
Master Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63052

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Stored XSS.This issue affects SimpLy Gallery: from n/a through <= 3.3.2.1.

PUBLISHED
Vendor
GalleryCreator
Product
SimpLy Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63051

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in sizam REHub Framework rehub-framework allows Retrieve Embedded Sensitive Data.This issue affects REHub Framework: from n/a through < 19.9.9.4.

PUBLISHED
Vendor
sizam
Product
REHub Framework
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63050

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam REHub Framework rehub-framework allows Stored XSS.This issue affects REHub Framework: from n/a through < 19.9.9.7.

PUBLISHED
Vendor
sizam
Product
REHub Framework
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6305

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_feature.php. The manipulation of the argument product_code leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Shoe Store
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-63049

Missing Authorization vulnerability in CridioStudio ListingPro Lead Form listingpro-lead-form allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ListingPro Lead Form: from n/a through <= 1.0.7.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro Lead Form
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63048

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Lead Form listingpro-lead-form allows DOM-Based XSS.This issue affects ListingPro Lead Form: from n/a through <= 1.0.7.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro Lead Form
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63047

Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.9.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63046

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows DOM-Based XSS.This issue affects ListingPro: from n/a through <= 2.9.9.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63045

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in averta Master Slider Pro masterslider allows DOM-Based XSS.This issue affects Master Slider Pro: from n/a through <= 3.7.12.

PUBLISHED
Vendor
averta
Product
Master Slider Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63044

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows DOM-Based XSS.This issue affects Xpro Elementor Addons: from n/a through <= 1.4.19.1.

PUBLISHED
Vendor
Xpro
Product
Xpro Elementor Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63043

Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.

PUBLISHED
Vendor
PickPlugins
Product
Post Grid and Gutenberg Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63042

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons allows Stored XSS.This issue affects Tutor LMS Elementor Addons: from n/a through <= 3.0.1.

PUBLISHED
Vendor
Themeum
Product
Tutor LMS Elementor Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63041

Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.

PUBLISHED
Vendor
Code Amp
Product
Forget About Shortcode Buttons
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63040

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Post Snippets post-snippets allows Cross Site Request Forgery.This issue affects Post Snippets: from n/a through <= 4.0.11.

PUBLISHED
Vendor
Saad Iqbal
Product
Post Snippets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6304

A vulnerability was found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /cart.php. The manipulation of the argument qty[] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Shoe Store
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-63039

Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.9.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63038

Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.40.

PUBLISHED
Vendor
Northern Beaches Websites
Product
WP Custom Admin Interface
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63037

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DFDevelopment Ronneby Theme Core ronneby-core allows DOM-Based XSS.This issue affects Ronneby Theme Core: from n/a through <= 1.5.68.

PUBLISHED
Vendor
DFDevelopment
Product
Ronneby Theme Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63036

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DFDevelopment Ronneby Theme Core ronneby-core allows PHP Local File Inclusion.This issue affects Ronneby Theme Core: from n/a through <= 1.5.68.

PUBLISHED
Vendor
DFDevelopment
Product
Ronneby Theme Core
Provider severity
HIGH
Conflicts
0

CVE-2025-63035

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplms_plugin allows DOM-Based XSS.This issue affects WPLMS: from n/a through <= 1.9.9.5.4.

PUBLISHED
Vendor
VibeThemes
Product
WPLMS
Provider severity
MEDIUM
Conflicts
0