CVE-2025-39355 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through 5.6.
CVSS: HIGH (8.5) EPSS Score: 0.03%
May 19th, 2025 (28 days ago)
|
CVE-2025-39352 |
Description: Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
CVSS: HIGH (8.2) EPSS Score: 0.05%
May 19th, 2025 (28 days ago)
|
CVE-2025-39350 |
Description: Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.
CVSS: HIGH (8.2) EPSS Score: 0.05%
May 19th, 2025 (28 days ago)
|
CVE-2025-32925 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FantasticPlugins SUMO Reward Points allows PHP Local File Inclusion.This issue affects SUMO Reward Points: from n/a through 30.7.0.
CVSS: HIGH (8.3) EPSS Score: 0.11%
May 19th, 2025 (28 days ago)
|
CVE-2025-32924 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy allows SQL Injection.This issue affects Revy: from n/a through 2.1.
CVSS: HIGH (8.5) EPSS Score: 0.03%
May 19th, 2025 (28 days ago)
|
CVE-2025-31027 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.
CVSS: HIGH (7.1) EPSS Score: 0.03%
May 19th, 2025 (28 days ago)
|
CVE-2025-47934 |
Description: OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously modified message can be passed to either `openpgp.verify` or `openpgp.decrypt`, causing these functions to return a valid signature verification result while returning data that was not actually signed. This flaw allows signature verifications of inline (non-detached) signed messages (using `openpgp.verify`) and signed-and-encrypted messages (using `openpgp.decrypt` with `verificationKeys`) to be spoofed, since both functions return extracted data that may not match the data that was originally signed. Detached signature verifications are not affected, as no signed data is returned in that case. In order to spoof a message, the attacker needs a single valid message signature (inline or detached) as well as the plaintext data that was legitimately signed, and can then construct an inline-signed message or signed-and-encrypted message with any data of the attacker's choice, which will appear as legitimately signed by affected versions of OpenPGP.js. In other words, any inline-signed message can be modified to return any other data (while still indicating that the signature was valid), and the same is true for signed+encrypted messages if the attacker can obtain a valid signature and encrypt a new message (of the attacker's choice) together with that signature. The issue has been patched in versions 5.11.3 and 6.1.1. Some workaroun...
CVSS: HIGH (8.7) EPSS Score: 0.01%
May 19th, 2025 (28 days ago)
|
CVE-2025-43839 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Messages Tool allows Reflected XSS.This issue affects BP Messages Tool: from n/a through 2.2.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
May 19th, 2025 (28 days ago)
|
CVE-2025-43837 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binti76 Total Donations allows Reflected XSS.This issue affects Total Donations: from n/a through 3.0.8.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
May 19th, 2025 (28 days ago)
|
CVE-2025-43836 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in confuzzledduck Syndicate Out allows Reflected XSS.This issue affects Syndicate Out: from n/a through 0.9.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
May 19th, 2025 (28 days ago)
|