Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Vulnerability List - Page 39

Found 2564 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-0515 Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Option Update cmsmastersBuzz Club – Night Club, DJ and Music Festival Event WordPress Theme Medium 4.3 2025-01-18 07:05:07 Deep Dive
CVE-2024-10799 Eventer <= 3.9.7 - Authenticated (Subscriber+) Arbitrary File Read imithemesEventer - WordPress Event & Booking Manager Plugin Medium 6.5 2025-01-17 05:29:28 Deep Dive
CVE-2024-13333 Advanced File Manager 5.2.12 - 5.2.13 - Authenticated (Subscriber+) Arbitrary File Upload saadiqbalAdvanced File Manager — Ultimate WordPress File Manager and Document Library Plugin High 7.5 2025-01-17 05:29:27 Deep Dive
CVE-2025-23961 WordPress WordPress Graphs & Charts Plugin <= 2.0.8 - Broken Access Control vulnerability wptaskerWordPress Graphs & Charts Medium 5.4 2025-01-16 20:08:11 Deep Dive
CVE-2025-23912 WordPress WordPress Custom Sidebar Plugin <= 2.3 - SQL Injection vulnerability Philipp SpeckWordPress Custom Sidebar High 8.5 2025-01-16 20:07:51 Deep Dive
CVE-2025-23913 WordPress Google Map Professional Plugin <= 1.0 - SQL Injection vulnerability pankajpragmaWordPress Google Map Professional High 8.5 2025-01-16 20:07:50 Deep Dive
CVE-2025-23842 WordPress WordPress Gallery Plugin plugin <= 1.4 - CSRF to Stored XSS vulnerability Nilesh ShiragaveWordPress Gallery Plugin High 7.1 2025-01-16 20:07:22 Deep Dive
CVE-2025-23828 WordPress WordPress Data Guard [Website Security] plugin <= 8 - CSRF to Stored XSS vulnerability sindhiWordPress Data Guard High 7.1 2025-01-16 20:07:18 Deep Dive
CVE-2025-23823 WordPress CNZZ&51LA for WordPress plugin <= 1.0.1 - CSRF to Stored XSS vulnerability jprintfCNZZ&51LA for WordPress High 7.1 2025-01-16 20:07:16 Deep Dive
CVE-2025-23510 WordPress WordPress Logging Service plugin <= 1.5.4 - CSRF to Stored Cross Site Scripting (XSS) vulnerability Jan ŠtětinaWordPress Logging Service High 7.1 2025-01-16 20:06:13 Deep Dive
CVE-2025-23435 WordPress Password Protect Plugin for WordPress plugin <= 0.8.1.0 - CSRF to Stored XSS vulnerability marcucciPassword Protect Plugin for WordPress High 7.1 2025-01-16 20:06:07 Deep Dive
CVE-2025-23423 WordPress SendGrid for WordPress plugin <= 1.4 - Broken Access Control vulnerability Smackcoders Inc.,SendGrid for WordPress Medium 4.3 2025-01-16 20:05:46 Deep Dive
CVE-2025-0170 DWT - Directory & Listing WordPress Theme <= 3.3.3 - Reflected Cross-Site Scripting scriptsbundleDWT - Directory & Listing WordPress Theme Medium 6.1 2025-01-16 01:49:03 Deep Dive
CVE-2025-22762 WordPress Octrace Support Pro plugin <= 1.2.7 - Cross Site Scripting (XSS) vulnerability OctraceWordPress HelpDesk & Support Ticket System Plugin – Octrace Support Medium 5.9 2025-01-15 15:23:24 Deep Dive
CVE-2025-0394 Groundhogg <= 3.7.3.5 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function trainingbusinessprosGroundhogg — CRM, Newsletters, and Marketing Automation High 8.8 2025-01-14 08:23:14 Deep Dive
CVE-2024-12412 Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin <= 2.2.1 - Reflected Cross-Site Scripting magepeopleteamBooking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment Medium 6.1 2025-01-11 07:21:53 Deep Dive
CVE-2024-12606 AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) <= 2.5 - Missing Authorization to Authenticated (Subscriber+) Settings Update opacewebdesignOpace AI Scribe: SEO Content Creator & Humaizer for OpenAI & Anthropic Medium 4.3 2025-01-10 03:21:30 Deep Dive
CVE-2024-12473 AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) <= 2.5 - Authenticated (Contributor+) SQL Injection opacewebdesignOpace AI Scribe: SEO Content Creator & Humaizer for OpenAI & Anthropic Medium 6.5 2025-01-10 03:21:30 Deep Dive
CVE-2025-22295 WordPress Tripetto plugin <= 8.0.6 - Cross Site Scripting (XSS) vulnerability TripettoWordPress form builder plugin for contact forms, surveys and quizzes – Tripetto 中危 -2025-01-09 15:39:33 Deep Dive
CVE-2025-22802 WordPress Email Templates Customizer YeeMail plugin <= 2.1.4 - Cross Site Scripting (XSS) vulnerability add-ons.orgEmail Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail Medium 6.5 2025-01-09 15:39:21 Deep Dive