| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-54679 | WordPress Neon Channel Product Customizer Free Plugin <= 2.0 - Arbitrary Content Deletion Vulnerability | vertim | Neon Channel Product Customizer Free | High | 7.5 | 2025-08-14 10:34:44 | Deep Dive |
| CVE-2025-54674 | WordPress Product Configurator for WooCommerce Plugin plugin <= 1.4.4 - Cross Site Request Forgery (CSRF) Vulnerability | mklacroix | Product Configurator for WooCommerce | Medium | 5.4 | 2025-08-14 10:34:41 | Deep Dive |
| CVE-2025-49887 | WordPress Product XML Feed Manager for WooCommerce Plugin <= 2.9.3 - Remote Code Execution (RCE) Vulnerability | WPFactory | Product XML Feed Manager for WooCommerce | Critical | 9.9 | 2025-08-14 10:34:07 | Deep Dive |
| CVE-2025-35970 | FUJIFILM FRONTIER DX400W 安全漏洞 | SEIKO EPSON | Multiple EPSON product | High | 7.5 | 2025-08-07 05:22:10 | Deep Dive |
| CVE-2025-30959 | WordPress Product XML Feed Manager for WooCommerce <= 2.9.2 - Broken Access Control Vulnerability | WPFactory | Product XML Feed Manager for WooCommerce | Medium | 6.5 | 2025-07-16 11:28:08 | Deep Dive |
| CVE-2025-24780 | WordPress Printcart Web to Print Product Designer for WooCommerce plugin <= 2.4.0 - SQL Injection Vulnerability | printcart | Printcart Web to Print Product Designer for WooCommerce | High | 8.5 | 2025-07-04 11:18:11 | Deep Dive |
| CVE-2025-49417 | WordPress WooCommerce Product Multi-Action plugin <= 1.3 - Deserialization of untrusted data Vulnerability | BestWpDeveloper | WooCommerce Product Multi-Action | Critical | 9.8 | 2025-07-04 11:17:49 | Deep Dive |
| CVE-2025-6842 | code-projects Product Inventory System edit_user.php sql injection | code-projects | Product Inventory System | Medium | 4.7 | 2025-06-29 03:00:09 | Deep Dive |
| CVE-2025-6841 | code-projects Product Inventory System edit_product.php sql injection | code-projects | Product Inventory System | Medium | 4.7 | 2025-06-29 02:31:06 | Deep Dive |
| CVE-2025-6840 | code-projects Product Inventory System Login index.php sql injection | code-projects | Product Inventory System | High | 7.3 | 2025-06-29 02:00:16 | Deep Dive |
| CVE-2025-49331 | WordPress eCommerce Product Catalog plugin <= 3.4.3 - PHP Object Injection Vulnerability | impleCode | eCommerce Product Catalog | High | 7.2 | 2025-06-17 15:01:23 | Deep Dive |
| CVE-2025-31059 | WordPress WBW Product Table PRO plugin <= 2.2.6 - SQL Injection vulnerability | woobewoo | WBW Product Table PRO | Critical | 9.3 | 2025-06-09 15:56:43 | Deep Dive |
| CVE-2025-48281 | WordPress MyStyle Custom Product Designer plugin <= 3.21.1 - SQL Injection Vulnerability | mystyleplatform | MyStyle Custom Product Designer | Critical | 9.3 | 2025-06-09 15:53:54 | Deep Dive |
| CVE-2025-49305 | WordPress Product Catalog Simple plugin <= 1.8.1 - Cross Site Scripting (XSS) Vulnerability | impleCode | Product Catalog Simple | Medium | 6.5 | 2025-06-06 12:53:48 | Deep Dive |
| CVE-2025-49287 | WordPress Product Feed for WooCommerce plugin <= 2.2.8 - Broken Access Control Vulnerability | WebToffee | Product Feed for WooCommerce | Medium | 4.3 | 2025-06-06 12:53:43 | Deep Dive |
| CVE-2025-5493 | Baison Channel Middleware Product ToJsonByControlName sql injection | Baison | Channel Middleware Product | Medium | 6.3 | 2025-06-03 10:31:07 | Deep Dive |
| CVE-2025-5285 | Product Subtitle for WooCommerce <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via htmlTag Parameter | spiderwares | Product Subtitle for WooCommerce | Medium | 6.4 | 2025-05-31 06:40:57 | Deep Dive |
| CVE-2025-4986 | Stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x | Dassault Systèmes | Product Manager | High | 8.7 | 2025-05-30 14:19:22 | Deep Dive |
| CVE-2025-4989 | Stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x | Dassault Systèmes | Product Manager | High | 8.7 | 2025-05-30 14:19:04 | Deep Dive |
| CVE-2025-4990 | Stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x | Dassault Systèmes | Product Manager | High | 8.7 | 2025-05-30 14:16:52 | Deep Dive |