Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62086

Missing Authorization vulnerability in akazanstev Яндекс Доставка (Boxberry) boxberry allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Яндекс Доставка (Boxberry): from n/a through <= 2.34.

PUBLISHED
Vendor
akazanstev
Product
Яндекс Доставка (Boxberry)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62085

Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BERTHA AI: from n/a through <= 1.13.

PUBLISHED
Vendor
Bertha AI – Andrew Palmer
Product
BERTHA AI
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62084

Cross-Site Request Forgery (CSRF) vulnerability in Imdad Next Web iNext Woo Pincode Checker inext-woo-pincode-checker allows Cross Site Request Forgery.This issue affects iNext Woo Pincode Checker: from n/a through <= 2.3.1.

PUBLISHED
Vendor
Imdad Next Web
Product
iNext Woo Pincode Checker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62083

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah BoomDevs WordPress Coming Soon coming-soon-by-boomdevs allows Retrieve Embedded Sensitive Data.This issue affects BoomDevs WordPress Coming Soon: from n/a through <= 1.0.4.

PUBLISHED
Vendor
WP Messiah
Product
BoomDevs WordPress Coming Soon
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62082

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generic Elements generic-elements-for-elementor allows Stored XSS.This issue affects Generic Elements: from n/a through <= 1.2.9.

PUBLISHED
Vendor
Nasir Uddin
Product
Generic Elements
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62081

Missing Authorization vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0.

PUBLISHED
Vendor
Channelize.io Team
Product
Live Shopping & Shoppable Videos For WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62080

Cross-Site Request Forgery (CSRF) vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Cross Site Request Forgery.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0.

PUBLISHED
Vendor
Channelize.io Team
Product
Live Shopping & Shoppable Videos For WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6208

The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption due to a resource management flaw. The vulnerability arises because the user-specified file limit (`num_files_limit`) is applied after all files in a directory are loaded into memory. This can lead to memory exhaustion and degraded performance, particularly in environments with limited resources. The issue is resolved in version 0.12.41.

PUBLISHED
Vendor
run-llama
Product
run-llama/llama_index
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62079

Missing Authorization vulnerability in Damian WP Export Categories & Taxonomies wp-export-categories-taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Export Categories & Taxonomies: from n/a through <= 1.0.3.

PUBLISHED
Vendor
Damian
Product
WP Export Categories & Taxonomies
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62078

Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout easy-upload-files-during-checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Upload Files During Checkout: from n/a through <= 3.0.0.

PUBLISHED
Vendor
Fahad Mahmood
Product
Easy Upload Files During Checkout
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62077

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SEOSEON EUROPE S.L Affiliate Link Tracker affiliate-link-tracker allows Stored XSS.This issue affects Affiliate Link Tracker: from n/a through <= 0.2.

PUBLISHED
Vendor
SEOSEON EUROPE S.L
Product
Affiliate Link Tracker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62076

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ido Kobelkowsky Simple Payment simple-payment.This issue affects Simple Payment: from n/a through <= 2.4.6.

PUBLISHED
Vendor
Ido Kobelkowsky
Product
Simple Payment
Provider severity
HIGH
Conflicts
0

CVE-2025-62075

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ido Kobelkowsky Simple Payment simple-payment.This issue affects Simple Payment: from n/a through <= 2.4.6.

PUBLISHED
Vendor
Ido Kobelkowsky
Product
Simple Payment
Provider severity
HIGH
Conflicts
0

CVE-2025-62074

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.71.

PUBLISHED
Vendor
Amauri
Product
WPMobile.App
Provider severity
HIGH
Conflicts
0

CVE-2025-62073

Missing Authorization vulnerability in Sovlix MeetingHub meetinghub.This issue affects MeetingHub: from n/a through <= 1.23.9.

PUBLISHED
Vendor
Sovlix
Product
MeetingHub
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62072

Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users.This issue affects Front End Users: from n/a through <= 3.2.33.

PUBLISHED
Vendor
Rustaurius
Product
Front End Users
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62071

Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-reviews-widget.This issue affects Social proof testimonials and reviews by Repuso: from n/a through <= 5.29.

PUBLISHED
Vendor
Repuso
Product
Social proof testimonials and reviews by Repuso
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62070

Missing Authorization vulnerability in WPXPO WowRevenue revenue.This issue affects WowRevenue: from n/a through <= 1.2.13.

PUBLISHED
Vendor
WPXPO
Product
WowRevenue
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6207

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PUBLISHED
Vendor
vjinfotech
Product
WP Import Export Lite
Provider severity
HIGH
Conflicts
0

CVE-2025-62069

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter.This issue affects MDTF: from n/a through <= 1.3.3.8.

PUBLISHED
Vendor
RealMag777
Product
MDTF
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62068

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.28.09.

PUBLISHED
Vendor
E2Pdf
Product
e2pdf
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62067

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Savory savory.This issue affects Savory: from n/a through <= 2.5.

PUBLISHED
Vendor
Elated-Themes
Product
Savory
Provider severity
HIGH
Conflicts
0

CVE-2025-62066

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Revolution revolution.This issue affects Revolution: from n/a through < 2.5.8.

PUBLISHED
Vendor
fuelthemes
Product
Revolution
Provider severity
HIGH
Conflicts
0

CVE-2025-62065

Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a through <= 1.6.5.

PUBLISHED
Vendor
Rometheme
Product
RTMKit
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62064

Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search & Go search-and-go allows Password Recovery Exploitation.This issue affects Search & Go: from n/a through <= 2.7.

PUBLISHED
Vendor
Elated-Themes
Product
Search & Go
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62063

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel Gutenberg Blocks wp-travel-blocks.This issue affects WP Travel Gutenberg Blocks: from n/a through <= 3.9.2.

PUBLISHED
Vendor
WP Travel
Product
WP Travel Gutenberg Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62062

Insertion of Sensitive Information Into Sent Data vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Retrieve Embedded Sensitive Data.This issue affects Easy Post Submission: from n/a through <= 1.7.0.

PUBLISHED
Vendor
ThemeRuby
Product
Easy Post Submission
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62061

Cross-Site Request Forgery (CSRF) vulnerability in impleCode Product Catalog Simple post-type-x.This issue affects Product Catalog Simple: from n/a through <= 1.8.4.

PUBLISHED
Vendor
impleCode
Product
Product Catalog Simple
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62060

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Tab Ultimate tabs-pro.This issue affects Tab Ultimate: from n/a through <= 1.8.

PUBLISHED
Vendor
Themepoints
Product
Tab Ultimate
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6206

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_image_editor_ajax_submit' function in all versions up to, and including, 2.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. In order to ex

PUBLISHED
Vendor
CodeRevolution
Product
Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit
Provider severity
HIGH
Conflicts
0

CVE-2025-62059

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force SureRank surerank.This issue affects SureRank: from n/a through <= 1.3.2.

PUBLISHED
Vendor
Brainstorm Force
Product
SureRank
Provider severity
HIGH
Conflicts
0

CVE-2025-62058

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through < 4.2.0.

PUBLISHED
Vendor
favethemes
Product
Houzez Theme - Functionality
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62057

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through < 4.2.0.

PUBLISHED
Vendor
favethemes
Product
Houzez Theme - Functionality
Provider severity
HIGH
Conflicts
0

CVE-2025-62056

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <= 1.0.1.

PUBLISHED
Vendor
blazethemes
Product
News Event
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62055

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Academist academist.This issue affects Academist: from n/a through < 1.3.

PUBLISHED
Vendor
Elated-Themes
Product
Academist
Provider severity
HIGH
Conflicts
0

CVE-2025-62054

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through <= 4.1.8.

PUBLISHED
Vendor
favethemes
Product
Houzez Theme - Functionality
Provider severity
HIGH
Conflicts
0

CVE-2025-62053

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through < 4.2.0.

PUBLISHED
Vendor
favethemes
Product
Houzez
Provider severity
HIGH
Conflicts
0

CVE-2025-62052

Missing Authorization vulnerability in Horea Radu One Page Express Companion one-page-express-companion.This issue affects One Page Express Companion: from n/a through <= 1.6.43.

PUBLISHED
Vendor
Horea Radu
Product
One Page Express Companion
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62051

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign Core u-design-core.This issue affects UDesign Core: from n/a through <= 4.14.1.

PUBLISHED
Vendor
AndonDesign
Product
UDesign Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62050

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.0.3.

PUBLISHED
Vendor
blazethemes
Product
Blogmatic
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6205

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

PUBLISHEDCISA KEV
Vendor
Dassault Systèmes
Product
DELMIA Apriso
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62049

Missing Authorization vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder.This issue affects Cost Calculator Builder: from n/a through <= 3.5.32.

PUBLISHED
Vendor
Stylemix
Product
Cost Calculator Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62048

Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform SmartCrawl smartcrawl-seo.This issue affects SmartCrawl: from n/a through <= 3.14.3.

PUBLISHED
Vendor
WPMU DEV - Your All-in-One WordPress Platform
Product
SmartCrawl
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62047

Unrestricted Upload of File with Dangerous Type vulnerability in Case-Themes Case Addons case-addons.This issue affects Case Addons: from n/a through < 1.3.0.

PUBLISHED
Vendor
Case-Themes
Product
Case Addons
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62046

Missing Authorization vulnerability in CodexThemes TheGem Demo Import (for WPBakery) thegem-importer.This issue affects TheGem Demo Import (for WPBakery): from n/a through <= 5.10.5.

PUBLISHED
Vendor
CodexThemes
Product
TheGem Demo Import (for WPBakery)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62045

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.10.5.1.

PUBLISHED
Vendor
CodexThemes
Product
TheGem Theme Elements (for WPBakery)
Provider severity
HIGH
Conflicts
0

CVE-2025-62044

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.10.5.1.

PUBLISHED
Vendor
CodexThemes
Product
TheGem Theme Elements (for WPBakery)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62043

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa allows DOM-Based XSS.This issue affects WPCasa: from n/a through 1.4.1.

PUBLISHED
Vendor
WPSight
Product
WPCasa
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62042

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post.This issue affects Event post: from n/a through <= 5.10.3.

PUBLISHED
Vendor
Bastien Ho
Product
Event post
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62041

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor) thegem-elementor.This issue affects TheGem (Elementor): from n/a through <= 5.10.5.1.

PUBLISHED
Vendor
CodexThemes
Product
TheGem (Elementor)
Provider severity
HIGH
Conflicts
0