CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-6740

Description: The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tmpD’ parameter in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.1)

EPSS Score: 0.09%

Source: CVE
July 4th, 2025 (2 days ago)

CVE-2025-52833

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS allows SQL Injection. This issue affects LMS: from n/a through 9.1.

CVSS: CRITICAL (9.3)

EPSS Score: 0.03%

Source: CVE
July 4th, 2025 (2 days ago)

CVE-2025-52832

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart Image Search allows SQL Injection. This issue affects NGG Smart Image Search: from n/a through 3.4.1.

CVSS: CRITICAL (9.3)

EPSS Score: 0.03%

Source: CVE
July 4th, 2025 (2 days ago)

CVE-2025-52831

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List Manager allows SQL Injection. This issue affects Video List Manager: from n/a through 1.7.

CVSS: CRITICAL (9.3)

EPSS Score: 0.03%

Source: CVE
July 4th, 2025 (2 days ago)

CVE-2025-52830

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bsecuretech bSecure – Your Universal Checkout allows Blind SQL Injection. This issue affects bSecure – Your Universal Checkout: from n/a through 1.7.9.

CVSS: CRITICAL (9.3)

EPSS Score: 0.03%

Source: CVE
July 4th, 2025 (2 days ago)

CVE-2025-52828

Description: Deserialization of Untrusted Data vulnerability in designthemes Red Art allows Object Injection. This issue affects Red Art: from n/a through 3.7.

CVSS: HIGH (8.8)

EPSS Score: 0.05%

Source: CVE
July 4th, 2025 (2 days ago)

CVE-2025-52813

Description: Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: from n/a through 4.6.5.

CVSS: HIGH (8.1)

EPSS Score: 0.04%

Source: CVE
July 4th, 2025 (2 days ago)

CVE-2025-52807

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects Kossy - Minimalist eCommerce WordPress Theme: from n/a through 1.45.

CVSS: HIGH (8.1)

EPSS Score: 0.12%

Source: CVE
July 4th, 2025 (2 days ago)

CVE-2025-52805

Description: Path Traversal vulnerability in VaultDweller Leyka allows PHP Local File Inclusion. This issue affects Leyka: from n/a through 3.31.9.

CVSS: HIGH (7.5)

EPSS Score: 0.03%

Source: CVE
July 4th, 2025 (2 days ago)

CVE-2025-52798

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch allows Reflected XSS. This issue affects JobSearch: from n/a through 2.9.0.

CVSS: HIGH (7.1)

EPSS Score: 0.03%

Source: CVE
July 4th, 2025 (2 days ago)