| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-66122 | WordPress Stylish Price List plugin <= 7.2.2 - Broken Access Control vulnerability | Design | Stylish Price List | Medium | 5.3 | 2025-12-16 08:12:53 | Deep Dive |
| CVE-2025-64248 | WordPress Request a Quote plugin <= 2.5.3 - Broken Access Control vulnerability | emarket-design | Request a Quote | - | - | 2025-12-16 08:12:49 | Deep Dive |
| CVE-2025-14050 | Design Import/Export <= 2.2 - Authenticated (Administrator+) SQL Injection via XML File Import | uxl | Design Import/Export – Styles, Templates, Template Parts and Patterns | Medium | 4.9 | 2025-12-13 03:20:27 | Deep Dive |
| CVE-2025-13403 | Employee Spotlight – Team Member Showcase & Meet the Team Plugin <= 5.1.3 - Missing Authorization to Authenticated (Subscriber+) Tracking Opt-In/Opt-Out Modification | emarket-design | Employee Spotlight – Team Member Showcase & Meet the Team Plugin | Medium | 4.3 | 2025-12-13 03:20:24 | Deep Dive |
| CVE-2025-66095 | WordPress KiviCare plugin <= 3.6.13 - SQL Injection vulnerability | Iqonic Design | KiviCare | High | 8.5 | 2025-11-21 12:30:00 | Deep Dive |
| CVE-2025-66091 | WordPress Stylish Cost Calculator plugin <= 8.1.5 - Cross Site Scripting (XSS) vulnerability | Design | Stylish Cost Calculator | 中危 | - | 2025-11-21 12:29:59 | Deep Dive |
| CVE-2025-13289 | 1000projects Design & Development of Student Database Management System SubjectDetails.php sql injection | 1000projects | Design & Development of Student Database Management System | Medium | 6.3 | 2025-11-17 16:02:05 | Deep Dive |
| CVE-2025-12090 | Employee Spotlight – Team Member Showcase & Meet the Team Plugin <= 5.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | emarket-design | Employee Spotlight – Team Member Showcase & Meet the Team Plugin | Medium | 6.4 | 2025-11-01 05:40:23 | Deep Dive |
| CVE-2025-12083 | CivicTheme Design System - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-113 | Drupal | CivicTheme Design System | - | - | 2025-10-29 23:14:34 | Deep Dive |
| CVE-2025-12082 | CivicTheme Design System - Moderately critical - Information disclosure - SA-CONTRIB-2025-112 | Drupal | CivicTheme Design System | - | - | 2025-10-29 23:14:19 | Deep Dive |
| CVE-2025-62899 | WordPress Photospace Responsive plugin <= 2.2.0 - Cross Site Scripting (XSS) vulnerability | THRIVE - Web Design Gold Coast | Photospace Responsive | Medium | 5.9 | 2025-10-27 01:33:50 | Deep Dive |
| CVE-2025-11872 | Material Design Iconic Font Integration <= 2 - Authenticated (Contributor+) Stored Cross-Site Scripting | mcostales84 | Material Design Iconic Font Integration | Medium | 6.4 | 2025-10-22 08:27:04 | Deep Dive |
| CVE-2025-11151 | Information Disclosure in Beyaz Computer's CityPLus | Beyaz Bilgisayar Software Design Industry and Trade Ltd. Co. | CityPLus | High | 8.2 | 2025-10-21 13:15:40 | Deep Dive |
| CVE-2025-9372 | Ultimate Multi Design Video Carousel <= 1.4 - Authenticated (Editor+) Stored Cross-Site Scripting | gbsdeveloper | Ultimate Multi Design Video Carousel | Medium | 5.5 | 2025-10-03 11:17:18 | Deep Dive |
| CVE-2025-6034 | Out of Bounds Read in DefaultFontOptions() in NI Circuit Design Suite | NI | Circuit Design Suite | High | 7.8 | 2025-09-30 16:07:22 | Deep Dive |
| CVE-2025-6033 | Memory Corruption issue in XML_Serialize() in NI Circuit Design Suite | NI | Circuit Design Suite | High | 7.8 | 2025-09-30 16:05:53 | Deep Dive |
| CVE-2025-6396 | XSS in Webbeyaz's web site | Webbeyaz Website Design | Website Software | Medium | 6.1 | 2025-09-26 14:12:17 | Deep Dive |
| CVE-2025-60157 | WordPress WP Ticket Customer Service Software & Support Ticket System Plugin <= 6.0.2 - Cross Site Scripting (XSS) Vulnerability | emarket-design | WP Ticket Customer Service Software & Support Ticket System | Medium | 6.5 | 2025-09-26 08:31:57 | Deep Dive |
| CVE-2025-58915 | WordPress Request a Quote plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability | emarket-design | Request a Quote | Medium | 6.5 | 2025-09-23 02:08:41 | Deep Dive |
| CVE-2025-9969 | Reflected XSS in Vizly Web Design's Real Estate Packages | Vizly Web Design | Real Estate Packages | High | 7.1 | 2025-09-19 11:26:08 | Deep Dive |