Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-47537

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF Invoices for WooCommerce + Drag and Drop Template Builder allows SQL Injection. This issue affects PDF Invoices for WooCommerce + Drag and Drop Template Builder: from n/a through 5.3.8.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47533

Description: Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina allows PHP Local File Inclusion. This issue affects Graphina: from n/a through 3.0.4.

CVSS: HIGH (8.1)

EPSS Score: 0.03%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47531

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47517

Description: Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal allows Stored XSS. This issue affects Accept Donations with PayPal: from n/a through 1.4.5.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47514

Description: Cross-Site Request Forgery (CSRF) vulnerability in Eli ELI's Related Posts Footer Links and Widget allows Stored XSS. This issue affects ELI's Related Posts Footer Links and Widget: from n/a through 1.2.04.20.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47510

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fullworks Display Eventbrite Events allows PHP Local File Inclusion. This issue affects Display Eventbrite Events: from n/a through n/a.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47508

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ruben Garcia GamiPress allows PHP Local File Inclusion. This issue affects GamiPress: from n/a through 7.3.7.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47498

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking allows PHP Local File Inclusion. This issue affects Hotel Booking: from n/a through 3.6.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47496

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress PublishPress Authors allows PHP Local File Inclusion. This issue affects PublishPress Authors: from n/a through 4.7.5.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47494

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON allows PHP Local File Inclusion. This issue affects EventON: from n/a through 2.4.1.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
May 7th, 2025 (about 1 month ago)