Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62132

Missing Authorization vulnerability in Strategy11 Team Tasty Recipes Lite tasty-recipes-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tasty Recipes Lite: from n/a through <= 1.1.5.

PUBLISHED
Vendor
Strategy11 Team
Product
Tasty Recipes Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62131

Missing Authorization vulnerability in Strategy11 Team Tasty Recipes Lite tasty-recipes-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tasty Recipes Lite: from n/a through <= 1.1.5.

PUBLISHED
Vendor
Strategy11 Team
Product
Tasty Recipes Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62130

Missing Authorization vulnerability in wpdiscover Accordion Slider Gallery accordion-slider-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider Gallery: from n/a through <= 2.7.

PUBLISHED
Vendor
wpdiscover
Product
Accordion Slider Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6213

The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.1 via the 'nppp_preload_cache_on_update' function. This is due to insufficient sanitization of the $_SERVER['HTTP_REFERERER'] parameter passed from the 'nppp_handle_fastcgi_cache_actions_admin_bar' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

PUBLISHED
Vendor
psauxit
Product
Nginx Cache Purge Preload
Provider severity
HIGH
Conflicts
0

CVE-2025-62129

Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.7.

PUBLISHED
Vendor
Magnigenie
Product
RestroPress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62128

Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans sitelock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteLock Security – WP Hardening, Login Security & Malware Scans: from n/a through <= 5.0.1.

PUBLISHED
Vendor
SiteLock
Product
SiteLock Security – WP Hardening, Login Security & Malware Scans
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62127

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Slider allows DOM-Based XSS. This issue affects WEN Logo Slider: from n/a through 3.4.0.

PUBLISHED
Vendor
WEN Themes
Product
WEN Logo Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62126

Insertion of Sensitive Information Into Sent Data vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Retrieve Embedded Sensitive Data.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3.

PUBLISHED
Vendor
Razvan Stanga
Product
Varnish/Nginx Proxy Caching
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62125

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anshul Gangrade Custom Background Changer custom-background-changer allows Stored XSS.This issue affects Custom Background Changer: from n/a through <= 3.0.

PUBLISHED
Vendor
Anshul Gangrade
Product
Custom Background Changer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62124

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soli WP Post Signature wp-post-signature allows Stored XSS.This issue affects WP Post Signature: from n/a through <= 0.4.1.

PUBLISHED
Vendor
Soli
Product
WP Post Signature
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62123

Cross-Site Request Forgery (CSRF) vulnerability in inkthemes WP Gmail SMTP wp-gmail-smtp allows Cross Site Request Forgery.This issue affects WP Gmail SMTP: from n/a through <= 1.0.7.

PUBLISHED
Vendor
inkthemes
Product
WP Gmail SMTP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62122

Missing Authorization vulnerability in solwininfotech Trash Duplicate and 301 Redirect trash-duplicate-and-301-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trash Duplicate and 301 Redirect: from n/a through <= 1.9.1.

PUBLISHED
Vendor
solwininfotech
Product
Trash Duplicate and 301 Redirect
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62121

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu Logo Slider , Logo Carousel , Logo showcase , Client Logo tc-logo-slider allows Stored XSS.This issue affects Logo Slider , Logo Carousel , Logo showcase , Client Logo: from n/a through <= 1.8.1.

PUBLISHED
Vendor
Imran Emu
Product
Logo Slider , Logo Carousel , Logo showcase , Client Logo
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62120

Cross-Site Request Forgery (CSRF) vulnerability in Rick Beckman OpenHook thesis-openhook allows Cross Site Request Forgery.This issue affects OpenHook: from n/a through <= 4.3.1.

PUBLISHED
Vendor
Rick Beckman
Product
OpenHook
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6212

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database module in versions 3.5.11 to 3.5.19 due to insufficient input sanitization and output escaping. The unfiltered field names are stored alongside the sanitized values. Later, the admin-side AJAX endpoint ajax_get_table_data() returns those raw names as JSON column headers, and the client-side DataTables renderer injects them directly into the DOM without any HTML encoding. This ma

PUBLISHED
Vendor
themefic
Product
Ultra Addons for Contact Form 7
Provider severity
HIGH
Conflicts
0

CVE-2025-62119

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ViitorCloud Technologies Pvt Ltd Add Featured Image Custom Link custom-url-to-featured-image allows DOM-Based XSS.This issue affects Add Featured Image Custom Link: from n/a through <= 2.0.0.

PUBLISHED
Vendor
ViitorCloud Technologies Pvt Ltd
Product
Add Featured Image Custom Link
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62118

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kcseopro AdWords Conversion Tracking Code adwords-conversion-tracking-code allows Stored XSS.This issue affects AdWords Conversion Tracking Code: from n/a through <= 1.0.

PUBLISHED
Vendor
kcseopro
Product
AdWords Conversion Tracking Code
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62117

Cross-Site Request Forgery (CSRF) vulnerability in Jayce53 EasyIndex easyindex allows Cross Site Request Forgery.This issue affects EasyIndex: from n/a through <= 1.1.1704.

PUBLISHED
Vendor
Jayce53
Product
EasyIndex
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62116

Missing Authorization vulnerability in quadlayers AI Copilot ai-copilot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Copilot: from n/a through <= 1.5.2.

PUBLISHED
Vendor
quadlayers
Product
AI Copilot
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62115

Missing Authorization vulnerability in ThemeBoy Hide Plugins hide-plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through <= 1.0.4.

PUBLISHED
Vendor
ThemeBoy
Product
Hide Plugins
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62114

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in marcelotorres Download Media Library download-media-library allows Retrieve Embedded Sensitive Data.This issue affects Download Media Library: from n/a through <= 0.2.1.

PUBLISHED
Vendor
marcelotorres
Product
Download Media Library
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62113

Cross-Site Request Forgery (CSRF) vulnerability in emendo_seb Co-marquage service-public.fr co-marquage-service-public allows Cross Site Request Forgery.This issue affects Co-marquage service-public.fr: from n/a through <= 0.5.77.

PUBLISHED
Vendor
emendo_seb
Product
Co-marquage service-public.fr
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62112

Cross-Site Request Forgery (CSRF) vulnerability in Merv Barrett Import into Easy Property Listings easy-property-listings-xml-csv-import allows Cross Site Request Forgery.This issue affects Import into Easy Property Listings: from n/a through <= 2.2.1.

PUBLISHED
Vendor
Merv Barrett
Product
Import into Easy Property Listings
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62111

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Extra Shortcodes extra-shortcodes allows Stored XSS.This issue affects Extra Shortcodes: from n/a through <= 2.2.

PUBLISHED
Vendor
webvitaly
Product
Extra Shortcodes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62110

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a through 3.3.

PUBLISHED
Vendor
Rescue Themes
Product
Rescue Shortcodes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6211

A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. This approach leads to hash collisions when structurally distinct chunks contain identical text, resulting in one chunk overwriting another. This can cause loss of semantically or legally important document content, breakage of parent-child chunk hierarchies, and inaccurate or hallucinated responses in AI outputs. The iss

PUBLISHED
Vendor
run-llama
Product
run-llama/llama_index
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62109

Insertion of Sensitive Information Into Sent Data vulnerability in INFINITUM FORM Geo Controller cf-geoplugin allows Retrieve Embedded Sensitive Data.This issue affects Geo Controller: from n/a through <= 8.9.4.

PUBLISHED
Vendor
INFINITUM FORM
Product
Geo Controller
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62108

Missing Authorization vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Add Custom Codes: from n/a through <= 4.80.

PUBLISHED
Vendor
SaifuMak
Product
Add Custom Codes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62107

Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page feather-login-page allows Cross Site Request Forgery.This issue affects Feather Login Page: from n/a through <= 1.1.7.

PUBLISHED
Vendor
PluginOps
Product
Feather Login Page
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62106

Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CRM System: from n/a through <= 3.4.5.

PUBLISHED
Vendor
Mario Peshev
Product
WP-CRM System
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62104

Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACF Galerie 4: from n/a through 1.4.2.

PUBLISHED
Vendor
Navneil Naicker
Product
ACF Galerie 4
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62103

Cross-Site Request Forgery (CSRF) vulnerability in wpmediadownload Media Library File Download media-download allows Cross Site Request Forgery.This issue affects Media Library File Download: from n/a through <= 1.4.

PUBLISHED
Vendor
wpmediadownload
Product
Media Library File Download
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62102

Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case dofollow-case-by-case allows Cross Site Request Forgery.This issue affects DoFollow Case by Case: from n/a through <= 3.5.1.

PUBLISHED
Vendor
apasionados
Product
DoFollow Case by Case
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62101

Cross-Site Request Forgery (CSRF) vulnerability in Omid Shamloo Pardakht Delkhah pardakht-delkhah allows Cross Site Request Forgery.This issue affects Pardakht Delkhah: from n/a through <= 3.0.0.

PUBLISHED
Vendor
Omid Shamloo
Product
Pardakht Delkhah
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62100

Missing Authorization vulnerability in themerain ThemeRain Core themerain-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeRain Core: from n/a through <= 1.1.9.

PUBLISHED
Vendor
themerain
Product
ThemeRain Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6210

A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path traversal. This flaw permits attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by exploiting hardlinks. The vulnerability arises from inadequate handling of hardlinks in the load_data() method, where the security checks fail to differentiate between real files and hardlinks. This issue is resolved in versi

PUBLISHED
Vendor
run-llama
Product
run-llama/llama_index
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62099

Missing Authorization vulnerability in approveme Signature Add-On for Gravity Forms gravity-signature-forms-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Signature Add-On for Gravity Forms: from n/a through <= 1.8.6.

PUBLISHED
Vendor
approveme
Product
Signature Add-On for Gravity Forms
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62098

Missing Authorization vulnerability in totalsoft Portfolio Gallery gallery-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery: from n/a through <= 1.4.8.

PUBLISHED
Vendor
totalsoft
Product
Portfolio Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62097

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in seothemes SEO Slider seo-slider allows DOM-Based XSS.This issue affects SEO Slider: from n/a through <= 1.1.1.

PUBLISHED
Vendor
seothemes
Product
SEO Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62096

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Maximum Products per User for WooCommerce maximum-products-per-user-for-woocommerce allows Stored XSS.This issue affects Maximum Products per User for WooCommerce: from n/a through <= 4.4.3.

PUBLISHED
Vendor
WPFactory
Product
Maximum Products per User for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62095

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in neilgee Bootstrap Modals bootstrap-modals allows Stored XSS.This issue affects Bootstrap Modals: from n/a through <= 1.3.2.

PUBLISHED
Vendor
neilgee
Product
Bootstrap Modals
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62094

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidthemes Void Elementor WHMCS Elements For Elementor Page Builder void-elementor-whmcs-elements.This issue affects Void Elementor WHMCS Elements For Elementor Page Builder: from n/a through <= 2.0.1.2.

PUBLISHED
Vendor
voidthemes
Product
Void Elementor WHMCS Elements For Elementor Page Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62093

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image&Video FullScreen Background lbg_fullscreen_fullwidth_slider allows SQL Injection.This issue affects Image&Video FullScreen Background: from n/a through <= 1.6.7.

PUBLISHED
Vendor
LambertGroup
Product
Image&Video FullScreen Background
Provider severity
HIGH
Conflicts
0

CVE-2025-62092

Missing Authorization vulnerability in Wiremo Wiremo woo-reviews-by-wiremo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wiremo: from n/a through <= 1.4.99.

PUBLISHED
Vendor
Wiremo
Product
Wiremo
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62091

Missing Authorization vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support serial-codes-generator-and-validator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through <= 2.8.2.

PUBLISHED
Vendor
Vollstart
Product
Serial Codes Generator and Validator with WooCommerce Support
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62090

Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons gutenverse-news allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons: from n/a through <= 3.0.2.

PUBLISHED
Vendor
Jegstudio
Product
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6209

A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the `encode_image` function in `generic_utils.py`. This vulnerability allows an attacker to manipulate the `image_path` input to read arbitrary files on the server, including sensitive system files. The issue arises due to improper validation or sanitization of the file path, enabling path traversal sequences to access files outside the intended directory. The vulnerability is fix

PUBLISHED
Vendor
run-llama
Product
run-llama/llama_index
Provider severity
HIGH
Conflicts
0

CVE-2025-62089

Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack mergado-marketing-pack allows Cross Site Request Forgery.This issue affects Mergado Pack: from n/a through <= 4.2.1.

PUBLISHED
Vendor
MERGADO
Product
Mergado Pack
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62088

Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: from n/a through <= 1.0.7.

PUBLISHED
Vendor
extendons
Product
WordPress & WooCommerce Scraper Plugin, Import Data from Any Site
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62087

Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard wb-sticky-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through <= 1.2.4.

PUBLISHED
Vendor
Web Builder 143
Product
Sticky Notes for WP Dashboard
Provider severity
MEDIUM
Conflicts
0