| CVE-2025-5092 | Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library | lightgalleryteam | LightGallery WP | Medium | 6.4 | 2025-11-20 06:38:42 | Deep Dive |
| CVE-2025-12497 | Premium Portfolio Features for Phlox theme <= 2.3.10 - Unauthenticated Local File Inclusion via args[extra_template_path] | averta | Premium Portfolio Features for Phlox theme | High | 8.1 | 2025-11-05 11:24:40 | Deep Dive |
| CVE-2025-11753 | Multi-language Responsive Portfolio WordPress <= 1.0 - Authenticated (Admin+) Stored Cross-Site Scripting | augustinfotech | Bootstrap Multi-language Responsive Portfolio | Medium | 4.4 | 2025-11-04 04:27:23 | Deep Dive |
| CVE-2025-59586 | WordPress Penci Portfolio Plugin <= 3.5 - Cross Site Scripting (XSS) Vulnerability | PenciDesign | Penci Portfolio | Medium | 6.5 | 2025-09-22 18:25:50 | Deep Dive |
| CVE-2025-57913 | WordPress Behance Portfolio Manager plugin <= 1.7.5 - Cross Site Scripting (XSS) vulnerability | eleopard | Behance Portfolio Manager | Medium | 6.5 | 2025-09-22 18:25:19 | Deep Dive |
| CVE-2025-57982 | WordPress Advance Portfolio Grid plugin <= 1.07.6 - Cross Site Scripting (XSS) vulnerability | WPBean | Advance Portfolio Grid | Medium | 5.9 | 2025-09-22 18:24:29 | Deep Dive |
| CVE-2025-58245 | WordPress Portfolio Plugin <= 2.58 - Cross Site Scripting (XSS) Vulnerability | bestweblayout | Portfolio | Medium | 5.9 | 2025-09-22 18:23:32 | Deep Dive |
| CVE-2025-10049 | Responsive Filterable Portfolio <= 1.0.24 - Authenticated (Admin+) Arbitrary File Upload | nik00726 | Responsive Filterable Portfolio | High | 7.2 | 2025-09-10 06:38:45 | Deep Dive |
| CVE-2025-49409 | WordPress Portfolio Manager Pro Plugin 3.8 - PHP Object Injection Vulnerability | brewlabs | Portfolio Manager Pro | Critical | 9.8 | 2025-08-20 08:03:47 | Deep Dive |
| CVE-2025-49410 | WordPress Portfolio Manager Pro Plugin 3.8 - Arbitrary File Upload Vulnerability | Imran Emu | Portfolio Manager Pro | Critical | 10.0 | 2025-08-20 08:03:46 | Deep Dive |
| CVE-2025-49420 | WordPress Ultra Portfolio - WordPress Plugin <= 6.7 - Cross Site Scripting (XSS) Vulnerability | themepassion | Ultra Portfolio | High | 7.1 | 2025-08-20 08:03:44 | Deep Dive |
| CVE-2025-52823 | WordPress Cube Portfolio Plugin <= 1.16.8 - SQL Injection Vulnerability | ovatheme | Cube Portfolio | High | 8.5 | 2025-08-14 10:33:56 | Deep Dive |
| CVE-2025-7644 | Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | bdthemes | Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery | Medium | 6.4 | 2025-07-22 04:25:08 | Deep Dive |
| CVE-2025-50061 | Oracle Construction and Engineering Suite 安全漏洞 | Oracle Corporation | Primavera P6 Enterprise Project Portfolio Management | Medium | 5.4 | 2025-07-15 19:27:35 | Deep Dive |
| CVE-2025-7046 | Portfolio for Elementor & Image Gallery | PowerFolio <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS | dotrex | PowerFolio – Portfolio & Image Gallery for Elementor | Medium | 6.4 | 2025-07-04 01:44:01 | Deep Dive |
| CVE-2025-4987 | Stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x | Dassault Systèmes | Project Portfolio Manager | High | 8.7 | 2025-06-16 07:22:02 | Deep Dive |
| CVE-2025-29010 | WordPress Behance Portfolio Manager plugin <= 1.7.5 - Broken Access Control vulnerability | eleopard | Behance Portfolio Manager | Medium | 4.3 | 2025-06-06 12:54:26 | Deep Dive |
| CVE-2025-4985 | Stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x | Dassault Systèmes | Project Portfolio Manager | High | 8.7 | 2025-05-30 14:19:28 | Deep Dive |
| CVE-2025-39359 | WordPress CWW Portfolio theme <= 1.3.1 - Local File Inclusion vulnerability | codeworkweb | CWW Portfolio | High | 7.5 | 2025-04-24 16:08:41 | Deep Dive |
| CVE-2025-32124 | WordPress Behance Portfolio Manager plugin <= 1.7.5 - SQL Injection vulnerability | eleopard | Behance Portfolio Manager | High | 7.6 | 2025-04-04 15:58:24 | Deep Dive |