CVE Alert: CVE-2024-12023
Vulnerability Summary: CVE-2024-12023 The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in...
Vulnerability Summary: CVE-2024-12023 The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in...
Vulnerability Summary: CVE-2024-13418 Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability...
Vulnerability Summary: CVE-2024-13420 Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check...
Vulnerability Summary: CVE-2025-1326 The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
Vulnerability Summary: CVE-2025-3510 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all...
Vulnerability Summary: CVE-2025-1327 The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,...
Vulnerability Summary: CVE-2024-13344 The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the...
Vulnerability Summary: CVE-2025-3708 Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remote attackers to...
Vulnerability Summary: CVE-2025-3858 The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all...
Vulnerability Summary: CVE-2025-3709 Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this...
Vulnerability Summary: CVE-2025-3748 The Taxonomy Chain Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pn_chain_menu...
Vulnerability Summary: CVE-2025-3707 The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to...
Ransomware Group: HELLCAT VICTIM NAME: www NOTE: No files or stolen information are by RedPacket Security. Any legal issues relating...
Company Name: RubyGems Company HackerOne URL: https://hackerone.com/rubygems Submitted By:jagat-singhLink to Submitters Profile:https://hackerone.com/jagat-singh Report Title:`/namesnsf` and all `/names*` files route to...
Ransomware Group: MONTI VICTIM NAME: American Eagle Logistics NOTE: No files or stolen information are by RedPacket Security. Any legal...
Vulnerability Summary: CVE-2025-3488 The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in...
Vulnerability Summary: CVE-2025-3438 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is...
Vulnerability Summary: CVE-2025-3513 The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which...
Vulnerability Summary: CVE-2025-47201 In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaScript code...
Vulnerability Summary: CVE-2025-3514 The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which...
Vulnerability Summary: CVE-2025-2812 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket...
Vulnerability Summary: CVE-2024-11142 Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forgery.This issue affects...
Vulnerability Summary: CVE-2024-13860 The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in...
Vulnerability Summary: CVE-2024-13859 The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in...