| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-13989 | WP Dropzone <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'callback' Shortcode Attribute | nazsabuz | WP Dropzone | Medium | 6.4 | 2025-12-12 03:20:42 | Deep Dive |
| CVE-2025-12775 | WP Dropzone <= 1.1.0 - Authenticated (Subscriber+) Arbitrary File Upload | nazsabuz | WP Dropzone | High | 8.8 | 2025-11-18 08:27:36 | Deep Dive |