CVE Alert: CVE-2025-49274
Vulnerability Summary: CVE-2025-49274 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awplife Neom Blog allows Reflected...
Vulnerability Summary: CVE-2025-49274 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awplife Neom Blog allows Reflected...
Vulnerability Summary: CVE-2025-4414 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters...
Vulnerability Summary: CVE-2025-49417 Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action allows Object Injection. This issue affects WooCommerce...
Vulnerability Summary: CVE-2025-49418 Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allows Server Side Request Forgery. This issue affects Allmart:...
Vulnerability Summary: CVE-2025-50032 Missing Authorization vulnerability in Paytiko - Payment Orchestration Platform Paytiko for WooCommerce allows Exploiting Incorrectly Configured Access...
Vulnerability Summary: CVE-2025-49870 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member...
Vulnerability Summary: CVE-2025-52776 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video List Manager allows...
Vulnerability Summary: CVE-2025-49867 Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes allows Privilege Escalation. This issue affects RealHomes: from n/a through...
Vulnerability Summary: CVE-2025-52796 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tggfref WP-Recall allows Reflected XSS....
Vulnerability Summary: CVE-2025-52798 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch allows Reflected XSS....
Vulnerability Summary: CVE-2025-52805 Path Traversal vulnerability in VaultDweller Leyka allows PHP Local File Inclusion. This issue affects Leyka: from n/a...
Vulnerability Summary: CVE-2025-52831 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List...
Vulnerability Summary: CVE-2025-50039 Missing Authorization vulnerability in vgwort VG WORT METIS allows Exploiting Incorrectly Configured Access Control Security Levels. This...
Vulnerability Summary: CVE-2025-52718 Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This...
Vulnerability Summary: CVE-2025-52830 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bsecuretech bSecure –...
Vulnerability Summary: CVE-2025-52828 Deserialization of Untrusted Data vulnerability in designthemes Red Art allows Object Injection. This issue affects Red Art:...
Vulnerability Summary: CVE-2025-7066 Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and...
Vulnerability Summary: CVE-2025-52807 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP...
Vulnerability Summary: CVE-2025-52813 Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects...
Vulnerability Summary: CVE-2025-52833 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS allows...
Vulnerability Summary: CVE-2025-6740 The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Vulnerability Summary: CVE-2025-48172 CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There...
Vulnerability Summary: CVE-2025-52832 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart...
Vulnerability Summary: CVE-2025-49809 mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment...