Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-63034

Missing Authorization vulnerability in Steve Truman Page View Count page-views-count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page View Count: from n/a through <= 2.9.0.

PUBLISHED
Vendor
Steve Truman
Product
Page View Count
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63033

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Riyadh Ahmed Make Section & Column Clickable For Elementor make-section-column-clickable-elementor allows Stored XSS.This issue affects Make Section & Column Clickable For Elementor: from n/a through <= 2.4.

PUBLISHED
Vendor
Riyadh Ahmed
Product
Make Section & Column Clickable For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63032

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thinkupthemes Consulting consulting allows Stored XSS.This issue affects Consulting: from n/a through <= 1.5.0.

PUBLISHED
Vendor
thinkupthemes
Product
Consulting
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63031

Missing Authorization vulnerability in WP Grids EasyTest convertpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EasyTest: from n/a through <= 1.0.1.

PUBLISHED
Vendor
WP Grids
Product
EasyTest
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63030

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal New User Approve new-user-approve allows Cross Site Request Forgery.This issue affects New User Approve: from n/a through <= 3.2.3.

PUBLISHED
Vendor
Saad Iqbal
Product
New User Approve
Provider severity
HIGH
Conflicts
1

CVE-2025-6303

A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /contactus1.php. The manipulation of the argument Message leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Shoe Store
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-63029

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows SQL Injection.This issue affects WCFM Marketplace: from n/a through <= 3.7.1.

PUBLISHED
Vendor
WC Lovers
Product
WCFM Marketplace
Provider severity
HIGH
Conflicts
0

CVE-2025-63028

Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.

PUBLISHED
Vendor
shinetheme
Product
Traveler
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63027

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcreations907 WBC907 Core wbc907-core allows Stored XSS.This issue affects WBC907 Core: from n/a through <= 3.4.1.

PUBLISHED
Vendor
webcreations907
Product
WBC907 Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant Theme Elements for Elementor grandrestaurant-elementor allows Stored XSS.This issue affects Grand Restaurant Theme Elements for Elementor: from n/a through <= 2.1.1.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Restaurant Theme Elements for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63025

Missing Authorization vulnerability in Xagio SEO Xagio SEO xagio-seo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xagio SEO: from n/a through <= 7.1.0.37.

PUBLISHED
Vendor
Xagio SEO
Product
Xagio SEO
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63024

Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.3.1.

PUBLISHED
Vendor
tychesoftwares
Product
Order Delivery Date for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63023

Missing Authorization vulnerability in Easy Payment Payment Gateway for PayPal on WooCommerce woo-paypal-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway for PayPal on WooCommerce: from n/a through <= 9.0.53.

PUBLISHED
Vendor
Easy Payment
Product
Payment Gateway for PayPal on WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63022

Missing Authorization vulnerability in topdevs.net Simple Like Page simple-facebook-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Like Page: from n/a through <= 1.5.3.

PUBLISHED
Vendor
topdevs.net
Product
Simple Like Page
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63021

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetipi Valenti Engine valenti-engine allows DOM-Based XSS.This issue affects Valenti Engine: from n/a through <= 1.0.3.

PUBLISHED
Vendor
codetipi
Product
Valenti Engine
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63020

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wayne Allen Postie postie allows Stored XSS.This issue affects Postie: from n/a through <= 1.9.73.

PUBLISHED
Vendor
Wayne Allen
Product
Postie
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6302

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Comment leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
EX1200T
Provider severity
HIGH
Conflicts
2

CVE-2025-63019

Insertion of Sensitive Information Into Sent Data vulnerability in Johan Jonk Stenström Cookies and Content Security Policy cookies-and-content-security-policy allows Retrieve Embedded Sensitive Data.This issue affects Cookies and Content Security Policy: from n/a through <= 2.34.

PUBLISHED
Vendor
Johan Jonk Stenström
Product
Cookies and Content Security Policy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63018

Missing Authorization vulnerability in wproyal Bard bard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bard: from n/a through <= 2.229.

PUBLISHED
Vendor
wproyal
Product
Bard
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63017

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes WerkStatt Plugin werkstatt-plugin allows PHP Local File Inclusion.This issue affects WerkStatt Plugin: from n/a through <= 1.6.6.

PUBLISHED
Vendor
fuelthemes
Product
WerkStatt Plugin
Provider severity
HIGH
Conflicts
0

CVE-2025-63016

Missing Authorization vulnerability in quadlayers QuadLayers TikTok Feed wp-tiktok-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QuadLayers TikTok Feed: from n/a through <= 4.6.5.

PUBLISHED
Vendor
quadlayers
Product
QuadLayers TikTok Feed
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63015

Missing Authorization vulnerability in paysera WooCommerce Payment Gateway - Paysera woo-payment-gateway-paysera allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Payment Gateway - Paysera: from n/a through <= 3.10.0.

PUBLISHED
Vendor
paysera
Product
WooCommerce Payment Gateway - Paysera
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63014

Cross-Site Request Forgery (CSRF) vulnerability in Serhii Pasyuk Gmedia Photo Gallery grand-media allows Cross Site Request Forgery.This issue affects Gmedia Photo Gallery: from n/a through <= 1.25.0.

PUBLISHED
Vendor
Serhii Pasyuk
Product
Gmedia Photo Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63013

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.

PUBLISHED
Vendor
ThimPress
Product
WP Hotel Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63012

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.2.8.

PUBLISHED
Vendor
ThimPress
Product
WP Hotel Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63011

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows DOM-Based XSS.This issue affects WP Hotel Booking: from n/a through <= 2.2.8.

PUBLISHED
Vendor
ThimPress
Product
WP Hotel Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63010

Server-Side Request Forgery (SSRF) vulnerability in ThemesInflow Hercules Core hercules-core allows Server Side Request Forgery.This issue affects Hercules Core : from n/a through <= 7.4.

PUBLISHED
Vendor
ThemesInflow
Product
Hercules Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6301

A vulnerability, which was classified as problematic, has been found in PHPGurukul Notice Board System 1.0. This issue affects some unknown processing of the file /admin/manage-notices.php of the component Add Notice. The manipulation of the argument Title/Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Notice Board System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-63009

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in yuvalo WP Google Analytics Events wp-google-analytics-events allows Retrieve Embedded Sensitive Data.This issue affects WP Google Analytics Events: from n/a through <= 2.8.2.

PUBLISHED
Vendor
yuvalo
Product
WP Google Analytics Events
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63008

Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.16.7.

PUBLISHED
Vendor
weDevs
Product
WP ERP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63007

Insertion of Sensitive Information Into Sent Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.4.1.

PUBLISHED
Vendor
Metagauss
Product
EventPrime
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63006

Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.4.1.

PUBLISHED
Vendor
Metagauss
Product
EventPrime
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63005

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas WordPress Tooltips wordpress-tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a through <= 10.9.3.

PUBLISHED
Vendor
Tomas
Product
WordPress Tooltips
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63004

Missing Authorization vulnerability in Skynet Technologies USA LLC All in One Accessibility all-in-one-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All in One Accessibility: from n/a through <= 1.15.

PUBLISHED
Vendor
Skynet Technologies USA LLC
Product
All in One Accessibility
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63003

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required Plugin north-plugin allows PHP Local File Inclusion.This issue affects North - Required Plugin: from n/a through <= 1.4.2.

PUBLISHED
Vendor
fuelthemes
Product
North - Required Plugin
Provider severity
HIGH
Conflicts
0

CVE-2025-63002

Missing Authorization vulnerability in wpforchurch Sermon Manager sermon-manager-for-wordpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sermon Manager: from n/a through <= 2.30.0.

PUBLISHED
Vendor
wpforchurch
Product
Sermon Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63001

Missing Authorization vulnerability in nicdark Hotel Booking nd-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Booking: from n/a through <= 3.8.

PUBLISHED
Vendor
nicdark
Product
Hotel Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2025-63000

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpforchurch Sermon Manager sermon-manager-for-wordpress allows Stored XSS.This issue affects Sermon Manager: from n/a through <= 2.30.0.

PUBLISHED
Vendor
wpforchurch
Product
Sermon Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6300

A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. This vulnerability affects unknown code of the file /admin/editempeducation.php. The manipulation of the argument yopgra leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Employee Record Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-62999

Missing Authorization vulnerability in themezaa Litho Addons litho-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Litho Addons: from n/a through <= 3.5.

PUBLISHED
Vendor
themezaa
Product
Litho Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62998

Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Retrieve Embedded Sensitive Data.This issue affects WP AI CoPilot: from n/a through <= 1.2.7.

PUBLISHED
Vendor
WP Messiah
Product
WP AI CoPilot
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62997

Insertion of Sensitive Information Into Sent Data vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Retrieve Embedded Sensitive Data.This issue affects WP EasyCart: from n/a through <= 5.8.11.

PUBLISHED
Vendor
levelfourdevelopment
Product
WP EasyCart
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62996

Missing Authorization vulnerability in Code Amp Custom Layouts – Post + Product grids made easy custom-layouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Layouts – Post + Product grids made easy: from n/a through <= 1.4.12.

PUBLISHED
Vendor
Code Amp
Product
Custom Layouts – Post + Product grids made easy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62995

Missing Authorization vulnerability in multiparcels MultiParcels Shipping For WooCommerce multiparcels-shipping-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiParcels Shipping For WooCommerce: from n/a through <= 1.30.12.

PUBLISHED
Vendor
multiparcels
Product
MultiParcels Shipping For WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62994

Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Retrieve Embedded Sensitive Data.This issue affects WP AI CoPilot: from n/a through <= 1.2.7.

PUBLISHED
Vendor
WP Messiah
Product
WP AI CoPilot
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62993

Missing Authorization vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notification for Telegram: from n/a through <= 3.5.1.

PUBLISHED
Vendor
rainafarai
Product
Notification for Telegram
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62992

Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backup: from n/a through <= 2.3.11.

PUBLISHED
Vendor
everestthemes
Product
Everest Backup
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62991

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thinkupthemes Minamaze minamaze allows Stored XSS.This issue affects Minamaze: from n/a through <= 1.10.1.

PUBLISHED
Vendor
thinkupthemes
Product
Minamaze
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62990

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Beaver Builder addons-for-beaver-builder allows Stored XSS.This issue affects Livemesh Addons for Beaver Builder: from n/a through <= 3.9.2.

PUBLISHED
Vendor
livemesh
Product
Livemesh Addons for Beaver Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6299

A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the argument targetAPSsid leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
N150RT
Provider severity
MEDIUM
Conflicts
2