CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-2262

Description: The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS: HIGH (7.3)

EPSS Score: 0.08%

Source: CVE
March 18th, 2025 (3 months ago)

CVE-2025-27281

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cookforweb All In Menu allows Blind SQL Injection. This issue affects All In Menu: from n/a through 1.1.5.

CVSS: HIGH (8.5)

EPSS Score: 0.04%

Source: CVE
March 15th, 2025 (3 months ago)

CVE-2025-26978

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound FS Poster. This issue affects FS Poster: from n/a through 6.5.8.

CVSS: HIGH (8.5)

EPSS Score: 0.03%

Source: CVE
March 15th, 2025 (3 months ago)

CVE-2025-26976

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.4.

CVSS: HIGH (8.5)

EPSS Score: 0.04%

Source: CVE
March 15th, 2025 (3 months ago)

CVE-2025-26972

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
March 15th, 2025 (3 months ago)

CVE-2025-26969

Description: Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.

CVSS: HIGH (8.3)

EPSS Score: 0.04%

Source: CVE
March 15th, 2025 (3 months ago)

CVE-2025-26961

Description: Missing Authorization vulnerability in NotFound Fresh Framework allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fresh Framework: from n/a through 1.70.0.

CVSS: HIGH (8.6)

EPSS Score: 0.05%

Source: CVE
March 15th, 2025 (3 months ago)

CVE-2025-26921

Description: Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager allows Object Injection. This issue affects Booking and Rental Manager: from n/a through 2.2.6.

CVSS: HIGH (8.8)

EPSS Score: 0.06%

Source: CVE
March 15th, 2025 (3 months ago)

CVE-2025-26886

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Authors allows SQL Injection. This issue affects PublishPress Authors: from n/a through 4.7.3.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
March 15th, 2025 (3 months ago)

CVE-2025-26556

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zzmaster WP AntiDDOS allows Reflected XSS. This issue affects WP AntiDDOS: from n/a through 2.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
March 15th, 2025 (3 months ago)