| CVE-2025-8568 | GMap - Venturit <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'h' Parameter | prabode | GMap Generator | Medium | 6.4 | 2025-08-12 02:24:48 | Deep Dive |
| CVE-2025-8685 | Wp chart generator <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpchart Shortcode | emilien | Wp chart generator | Medium | 6.4 | 2025-08-12 02:24:46 | Deep Dive |
| CVE-2025-7941 | PHPGurukul Time Table Generator System profile.php cross site scripting | PHPGurukul | Time Table Generator System | Low | 3.5 | 2025-07-21 21:32:07 | Deep Dive |
| CVE-2025-6781 | Copymatic – AI Content Writer & Generator <= 2.1 - Cross-Site Request Forgery to Settings Update | ryanfaber | Copymatic – AI Content Writer & Generator | Medium | 4.3 | 2025-07-18 04:23:03 | Deep Dive |
| CVE-2025-6290 | Tournament Bracket Generator <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via bracket Shortcode | blakelong | Tournament Bracket Generator | Medium | 6.4 | 2025-06-26 02:06:34 | Deep Dive |
| CVE-2025-49234 | WordPress WP Dummy Content Generator plugin <= 3.4.6 - Arbitrary User Deletion vulnerability | Deepak anand | WP Dummy Content Generator | Medium | 6.5 | 2025-06-17 15:01:31 | Deep Dive |
| CVE-2025-49312 | WordPress Echo RSS Feed Post Generator Plugin for WordPress plugin <= 5.4.8.1 - Reflected Cross Site Scripting (XSS) vulnerability | CodeRevolution | Echo RSS Feed Post Generator Plugin for WordPress | High | 7.1 | 2025-06-17 15:01:24 | Deep Dive |
| CVE-2025-4592 | AI Image Lab – Free AI Image Generator <= 1.0.6 - Cross-Site Request Forgery to API Key Update | aspengrovestudios | AI Image Lab – Free AI Image Generator | Medium | 4.3 | 2025-06-14 08:23:25 | Deep Dive |
| CVE-2025-5288 | REST API | Custom API Generator For Cross Platform And Import Export In WP 1.0.0 - 2.0.3 - Missing Authorization to Unauthenticated Privilege Escalation via process_handler Function | weboccults | REST API | Custom API Generator For Cross Platform And Import Export In WP | Critical | 9.8 | 2025-06-13 01:47:46 | Deep Dive |
| CVE-2025-49294 | WordPress Crawlomatic Multisite Scraper Post Generator plugin <= 2.6.8.2 - Sensitive Data Exposure via Log Exposure vulnerability | CodeRevolution | Crawlomatic Multisite Scraper Post Generator | Medium | 5.3 | 2025-06-06 12:53:46 | Deep Dive |
| CVE-2025-49293 | WordPress Crawlomatic Multisite Scraper Post Generator plugin <= 2.6.8.2 - Broken Access Control Vulnerability | CodeRevolution | Crawlomatic Multisite Scraper Post Generator | Medium | 4.3 | 2025-06-06 12:53:46 | Deep Dive |
| CVE-2025-5008 | projectworlds Online Time Table Generator add_teacher.php sql injection | projectworlds | Online Time Table Generator | High | 7.3 | 2025-05-20 23:00:12 | Deep Dive |
| CVE-2025-5004 | projectworlds Online Time Table Generator add_course.php sql injection | projectworlds | Online Time Table Generator | High | 7.3 | 2025-05-20 22:31:04 | Deep Dive |
| CVE-2025-5003 | projectworlds Online Time Table Generator semester_ajax.php sql injection | projectworlds | Online Time Table Generator | High | 7.3 | 2025-05-20 22:00:14 | Deep Dive |
| CVE-2025-4391 | Echo RSS Feed Post Generator <= 5.4.8.1 - Unauthenticated Arbitrary File Upload | CodeRevolution | Echo RSS Feed Post Generator | Critical | 9.8 | 2025-05-17 05:30:34 | Deep Dive |
| CVE-2025-4389 | Crawlomatic Multipage Scraper Post Generator <= 2.6.8.1 - Unauthenticated Arbitrary File Upload | CodeRevolution | Crawlomatic Multipage Scraper Post Generator | Critical | 9.8 | 2025-05-17 05:30:33 | Deep Dive |
| CVE-2025-46516 | WordPress Twitter Card Generator plugin <= 1.0.5 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | silencecm | Twitter Card Generator | High | 7.1 | 2025-04-24 16:08:57 | Deep Dive |
| CVE-2025-39521 | WordPress Contact Form vCard Generator plugin <= 2.4 - Reflected Cross Site Scripting (XSS) vulnerability | Ashish Ajani | Contact Form vCard Generator | High | 7.1 | 2025-04-17 15:46:56 | Deep Dive |
| CVE-2025-32929 | WordPress Barcode Generator for WooCommerce plugin <= 2.0.4 - Arbitrary Content Deletion vulnerability | Dmitry V. (CEO of "UKR Solution") | Barcode Generator for WooCommerce | High | 7.5 | 2025-04-15 11:58:10 | Deep Dive |
| CVE-2025-32228 | WordPress Ai Image Alt Text Generator for WP plugin <= 1.1.9 - Sensitive Data Exposure vulnerability | WP Messiah | Ai Image Alt Text Generator for WP | Medium | 4.3 | 2025-04-10 08:09:46 | Deep Dive |