CVE-2025-32668 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.
CVSS: HIGH (8.1) EPSS Score: 0.15%
April 10th, 2025 (2 months ago)
|
CVE-2025-32160 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON. This issue affects EventON: from n/a through 2.3.2.
CVSS: HIGH (7.5) EPSS Score: 0.13%
April 10th, 2025 (2 months ago)
|
CVE-2025-32158 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aThemes aThemes Addons for Elementor. This issue affects aThemes Addons for Elementor: from n/a through 1.0.15.
CVSS: HIGH (7.5) EPSS Score: 0.13%
April 10th, 2025 (2 months ago)
|
CVE-2025-32145 |
Description: Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently allows Object Injection. This issue affects WpEvently: from n/a through 4.3.5.
CVSS: HIGH (8.8) EPSS Score: 0.05%
April 10th, 2025 (2 months ago)
|
CVE-2025-32128 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aaronfrey Nearby Locations allows SQL Injection. This issue affects Nearby Locations: from n/a through 1.1.1.
CVSS: HIGH (7.6) EPSS Score: 0.04%
April 10th, 2025 (2 months ago)
|
CVE-2025-32119 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate Payments for WooCommerce allows Blind SQL Injection. This issue affects CardGate Payments for WooCommerce: from n/a through 3.2.1.
CVSS: HIGH (8.2) EPSS Score: 0.03%
April 10th, 2025 (2 months ago)
|
CVE-2025-32116 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studi7 QR Master allows Reflected XSS. This issue affects QR Master: from n/a through 1.0.5.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 10th, 2025 (2 months ago)
|
CVE-2025-32115 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping Content Light allows Reflected XSS. This issue affects Popping Content Light: from n/a through 2.4.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 10th, 2025 (2 months ago)
|
CVE-2025-32114 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5sterrenspecialist 5sterrenspecialist allows Reflected XSS. This issue affects 5sterrenspecialist: from n/a through 1.3.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 10th, 2025 (2 months ago)
|
CVE-2025-31524 |
Description: Incorrect Privilege Assignment vulnerability in NotFound WP User Profiles allows Privilege Escalation. This issue affects WP User Profiles: from n/a through 2.6.2.
CVSS: HIGH (8.8) EPSS Score: 0.04%
April 10th, 2025 (2 months ago)
|