| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-52795 | WordPress WP Front User Submit / Front Editor plugin <= 5.0.6 - Cross Site Request Forgery (CSRF) vulnerability | aharonyan | WP Front User Submit / Front Editor | High | 7.1 | 2025-06-20 15:03:40 | Deep Dive |
| CVE-2025-4187 | UserPro - Community and User Profile WordPress Plugin <= 5.1.10 - Unauthenticated Arbitrary File Read | - | UserPro - Community and User Profile WordPress Plugin | Medium | 5.9 | 2025-06-14 08:23:23 | Deep Dive |
| CVE-2025-3055 | WP User Frontend Pro <= 4.1.3 - Authenticated (Subscriber+) Arbitrary File Deletion | wedevs | WP User Frontend Pro | High | 8.1 | 2025-06-05 05:23:01 | Deep Dive |
| CVE-2025-3054 | WP User Frontend Pro <= 4.1.3 - Authenticated (Subscriber+) Arbitrary File Upload | wedevs | WP User Frontend Pro | High | 8.8 | 2025-06-05 05:23:00 | Deep Dive |
| CVE-2025-4671 | Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Medium | 6.4 | 2025-06-03 11:22:26 | Deep Dive |
| CVE-2024-8008 | Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products via JDBC User Store Connection Validation | WSO2 | WSO2 Enterprise Integrator | Medium | 5.2 | 2025-06-02 16:48:12 | Deep Dive |
| CVE-2025-47611 | WordPress User Meta plugin <= 3.1.2 - Reflected Cross Site Scripting (XSS) vulnerability | Khaled | User Meta | High | 7.1 | 2025-05-23 12:43:28 | Deep Dive |
| CVE-2025-48340 | WordPress User Profile Meta Manager plugin <= 1.02 - CSRF to Privilege Escalation vulnerability | Danny Vink | User Profile Meta Manager | Critical | 9.8 | 2025-05-19 20:33:07 | Deep Dive |
| CVE-2025-4934 | PHPGurukul User Registration & Login and User Management System edit-profile.php sql injection | PHPGurukul | User Registration & Login and User Management System | High | 7.3 | 2025-05-19 13:31:06 | Deep Dive |
| CVE-2024-0970 | User Activity Tracking and Log < 4.1.4 - IP Spoofing | Unknown | User Activity Tracking and Log | - | - | 2025-05-15 20:09:33 | Deep Dive |
| CVE-2024-6708 | Profile Builder <= 3.12.0 - Admin+ Stored Cross Site Scripting | Unknown | User Profile Builder | - | - | 2025-05-15 20:07:09 | Deep Dive |
| CVE-2025-30176 | Siemens多款产品 缓冲区错误漏洞 | Siemens | SIMATIC PCS neo V4.1 | High | 7.5 | 2025-05-13 09:38:40 | Deep Dive |
| CVE-2025-30175 | Siemens多款产品 缓冲区错误漏洞 | Siemens | SIMATIC PCS neo V4.1 | High | 7.5 | 2025-05-13 09:38:38 | Deep Dive |
| CVE-2025-30174 | Siemens多款产品 缓冲区错误漏洞 | Siemens | SIMATIC PCS neo V4.1 | High | 7.5 | 2025-05-13 09:38:37 | Deep Dive |
| CVE-2025-4513 | Catalyst User Key Authentication Plugin Logout logout.php redirect | Catalyst | User Key Authentication Plugin | Medium | 4.3 | 2025-05-10 19:31:04 | Deep Dive |
| CVE-2025-47676 | WordPress User Login History plugin <= 2.1.6 - Cross Site Scripting (XSS) Vulnerability | Faiyaz Alam | User Login History | Medium | 6.5 | 2025-05-07 14:20:53 | Deep Dive |
| CVE-2025-47617 | WordPress WP Front User Submit / Front Editor plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability | aharonyan | WP Front User Submit / Front Editor | Medium | 5.9 | 2025-05-07 14:20:33 | Deep Dive |
| CVE-2025-47592 | WordPress Legal Terms and Conditions Popup for User Login and WooCommerce Checkout – TPUL plugin <= 2.0.8 - Cross Site Scripting (XSS) Vulnerability | Árpád Lehel Mátyus | Terms Popup On User Login | Medium | 5.9 | 2025-05-07 14:20:24 | Deep Dive |
| CVE-2025-3281 | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion | wpeverest | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | Medium | 5.3 | 2025-05-06 07:24:22 | Deep Dive |
| CVE-2025-46459 | WordPress Confirm User Registration plugin <= 2.1.5 - Cross Site Scripting (XSS) Vulnerability | Ralf Hortt | Confirm User Registration | Medium | 5.9 | 2025-04-24 16:09:20 | Deep Dive |