| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-2628 | All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login <= 2.2.5 - Authentication Bypass | cyberlord92 | All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login | Critical | 9.8 | 2026-03-03 01:21:50 | Deep Dive |
| CVE-2025-13408 | Foxtool All-in-One: Contact chat button, Custom login, Media optimize images <= 2.5.2 - Cross-Site Request Forgery to Google OAuth Connection | foxtheme | Foxtool All-in-One: Contact chat button, Custom login, Media optimize images | Medium | 4.3 | 2025-12-12 03:20:44 | Deep Dive |
| CVE-2025-58595 | WordPress All In One Login plugin <= 2.0.8 - Bypass Vulnerability vulnerability | Saad Iqbal | All In One Login | 中危 | - | 2025-11-06 15:54:22 | Deep Dive |
| CVE-2025-23974 | WordPress One-Login plugin <= 1.4 - Privilege Escalation Vulnerability | ifkooo | One-Login | High | 8.1 | 2025-06-09 15:56:57 | Deep Dive |
| CVE-2025-23587 | WordPress all-in-one-box-login plugin <= 2.0.1 - Reflected Cross Site Scripting (XSS) vulnerability | Ashek Al Mahmud | all-in-one-box-login | High | 7.1 | 2025-03-03 13:30:14 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2023-38476 | WordPress Client Portal : SuiteDash Direct Login Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS) | SuiteDash :: ONE Dashboard® | Client Portal : SuiteDash Direct Login | Medium | 5.9 | 2023-09-03 11:43:04 | Deep Dive |