| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-28912 | WordPress Custom Dashboard Page plugin <= 1.0 - Cross Site Request Forgery (CSRF) vulnerability | Muntasir Rahman | Custom Dashboard Page | Medium | 4.3 | 2025-03-11 21:00:58 | Deep Dive |
| CVE-2025-26911 | WordPress System Dashboard plugin <= 2.8.18 - Sensitive Data Exposure vulnerability | Bowo | System Dashboard | Medium | 4.3 | 2025-02-25 14:17:54 | Deep Dive |
| CVE-2024-13379 | C9 Admin Dashboard <= 1.3.5 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | ttoomey | C9 Admin Dashboard | Medium | 6.4 | 2025-02-21 03:21:21 | Deep Dive |
| CVE-2024-13390 | ADFO – Custom data in admin dashboard <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | giuliopanda | ADFO – Custom data in admin dashboard | Medium | 6.4 | 2025-02-19 07:32:07 | Deep Dive |
| CVE-2025-23525 | WordPress Kv Compose Email From Dashboard plugin <= 1.1 - Reflected Cross Site Scripting (XSS) vulnerability | kvvaradha | Kv Compose Email From Dashboard | High | 7.1 | 2025-02-14 12:44:29 | Deep Dive |
| CVE-2025-23474 | WordPress Live Dashboard plugin <= 0.3.3 - Reflected Cross Site Scripting (XSS) vulnerability | Mike Martel | Live Dashboard | High | 7.1 | 2025-02-14 12:44:28 | Deep Dive |
| CVE-2025-25135 | WordPress Custom Links On Admin Dashboard Toolbar plugin <= 3.3 - CSRF to Stored XSS vulnerability | Victor Barkalov | Custom Links On Admin Dashboard Toolbar | High | 7.1 | 2025-02-07 10:11:52 | Deep Dive |
| CVE-2024-12299 | System Dashboard <= 2.8.17 - Reflected Cross-Site Scripting via Filename Parameter | qriouslad | System Dashboard | Medium | 6.1 | 2025-01-30 13:42:07 | Deep Dive |
| CVE-2025-23730 | WordPress FLX Dashboard Groups plugin <= 0.0.7 - Reflected Cross Site Scripting (XSS) vulnerability | flx0 | FLX Dashboard Groups | High | 7.1 | 2025-01-23 15:29:42 | Deep Dive |
| CVE-2025-23917 | WordPress Chamber Dashboard Business Directory Plugin <= 3.3.10 - Broken Access Control vulnerability | Chandrika Guntur, Morgan Kay | Chamber Dashboard Business Directory | Medium | 5.4 | 2025-01-16 20:07:58 | Deep Dive |
| CVE-2024-11452 | Chamber Dashboard Business Directory <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting | gwendydd | Chamber Dashboard Business Directory | Medium | 6.4 | 2025-01-16 03:27:22 | Deep Dive |
| CVE-2024-56024 | WordPress Custom Dashboard Widget plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability | DuoGeek | Custom Dashboard Widget | High | 7.1 | 2025-01-02 12:01:13 | Deep Dive |
| CVE-2024-56071 | WordPress Simple Dashboard plugin <= 2.0 - Privilege Escalation vulnerability | mikeleembruggen | Simple Dashboard | Critical | 9.8 | 2024-12-31 12:44:33 | Deep Dive |
| CVE-2024-10783 | MainWP Child <= 5.3.3 - Missing Authorization to Unauthenticated Privilege Escalation | mainwp | MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites | High | 8.1 | 2024-12-13 09:27:29 | Deep Dive |
| CVE-2024-10708 | System Dashboard < 2.8.15 - Admin+ Path Traversal | Unknown | System Dashboard | 中危 | - | 2024-12-10 06:00:02 | Deep Dive |
| CVE-2024-11107 | System Dashboard < 2.8.15 - Unauthenticated Stored XSS | Unknown | System Dashboard | 中危 | - | 2024-12-10 06:00:02 | Deep Dive |
| CVE-2024-12359 | code-projects Admin Dashboard vendor_management.php cross site scripting | code-projects | Admin Dashboard | Low | 3.5 | 2024-12-09 05:00:14 | Deep Dive |
| CVE-2024-43338 | WordPress Crowdsignal Polls & Ratings plugin <= 3.1.3 - Cross Site Request Forgery (CSRF) vulnerability | Automattic | Crowdsignal Dashboard – Polls, Surveys & more | Medium | 4.3 | 2024-11-19 16:32:36 | Deep Dive |
| CVE-2024-51860 | WordPress Custom Dashboard Widget plugin <= 1.0.0 - Stored Cross Site Scripting (XSS) vulnerability | DuoGeek | Custom Dashboard Widget | Medium | 6.5 | 2024-11-19 16:31:29 | Deep Dive |
| CVE-2024-8959 | WP Adminify – Best WordPress Custom Dashboard Plugin <= 4.0.1.6 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | litonice13 | WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer | Medium | 6.4 | 2024-10-24 11:34:09 | Deep Dive |