| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-12185 | StaffList <= 3.2.6 - Authenticated (Admin+) Stored Cross-Site Scripting | era404 | StaffList | Medium | 4.4 | 2025-11-27 05:17:38 | Deep Dive |
| CVE-2025-52734 | WordPress CropRefine Plugin <= 1.2.1 - Cross Site Scripting (XSS) Vulnerability | ERA404 | CropRefine | High | 7.1 | 2025-10-22 14:32:22 | Deep Dive |
| CVE-2025-57918 | WordPress LinkedInclude Plugin <= 3.0.4 - Cross Site Request Forgery (CSRF) Vulnerability | ERA404 | LinkedInclude | High | 7.1 | 2025-09-22 18:25:15 | Deep Dive |
| CVE-2025-32255 | WordPress StaffList plugin <= 3.2.7 - Sensitive Data Exposure vulnerability | ERA404 | StaffList | Medium | 5.3 | 2025-04-04 15:59:29 | Deep Dive |
| CVE-2025-32232 | WordPress StaffList plugin <= 3.2.7 - Broken Access Control vulnerability | ERA404 | StaffList | Medium | 4.3 | 2025-04-04 15:59:18 | Deep Dive |
| CVE-2025-23845 | WordPress ImageMeta Plugin <= 1.1.2 - Reflected Cross Site Scripting (XSS) vulnerability | ERA404 | ImageMeta | High | 7.1 | 2025-02-17 11:38:52 | Deep Dive |
| CVE-2024-13749 | StaffList <= 3.2.3 - Cross-Site Request Forgery to Reflected Cross-Site Scripting | era404 | StaffList | Medium | 6.1 | 2025-02-12 03:21:39 | Deep Dive |