CVE-2025-6740 |
Description: The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tmpD’ parameter in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.1) EPSS Score: 0.09%
July 4th, 2025 (2 days ago)
|
CVE-2025-52833 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS allows SQL Injection. This issue affects LMS: from n/a through 9.1.
CVSS: CRITICAL (9.3) EPSS Score: 0.03%
July 4th, 2025 (2 days ago)
|
CVE-2025-52832 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart Image Search allows SQL Injection. This issue affects NGG Smart Image Search: from n/a through 3.4.1.
CVSS: CRITICAL (9.3) EPSS Score: 0.03%
July 4th, 2025 (2 days ago)
|
CVE-2025-52831 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List Manager allows SQL Injection. This issue affects Video List Manager: from n/a through 1.7.
CVSS: CRITICAL (9.3) EPSS Score: 0.03%
July 4th, 2025 (2 days ago)
|
CVE-2025-52830 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bsecuretech bSecure – Your Universal Checkout allows Blind SQL Injection. This issue affects bSecure – Your Universal Checkout: from n/a through 1.7.9.
CVSS: CRITICAL (9.3) EPSS Score: 0.03%
July 4th, 2025 (2 days ago)
|
CVE-2025-52828 |
Description: Deserialization of Untrusted Data vulnerability in designthemes Red Art allows Object Injection. This issue affects Red Art: from n/a through 3.7.
CVSS: HIGH (8.8) EPSS Score: 0.05%
July 4th, 2025 (2 days ago)
|
CVE-2025-52813 |
Description: Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: from n/a through 4.6.5.
CVSS: HIGH (8.1) EPSS Score: 0.04%
July 4th, 2025 (2 days ago)
|
CVE-2025-52807 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects Kossy - Minimalist eCommerce WordPress Theme: from n/a through 1.45.
CVSS: HIGH (8.1) EPSS Score: 0.12%
July 4th, 2025 (2 days ago)
|
CVE-2025-52805 |
Description: Path Traversal vulnerability in VaultDweller Leyka allows PHP Local File Inclusion. This issue affects Leyka: from n/a through 3.31.9.
CVSS: HIGH (7.5) EPSS Score: 0.03%
July 4th, 2025 (2 days ago)
|
CVE-2025-52798 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch allows Reflected XSS. This issue affects JobSearch: from n/a through 2.9.0.
CVSS: HIGH (7.1) EPSS Score: 0.03%
July 4th, 2025 (2 days ago)
|