NA - CVE-2025-1302 - Versions of the package jsonpath-plus before...
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by...
NA - CVE-2024-13208 - The Maps Plugin using Google Maps for WordPress...
The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform...
NA - CVE-2024-13306 - The Maps Plugin using Google Maps for WordPress...
The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform...
Critical - CVE-2024-13513 - The Oliver POS – A WooCommerce Point of Sale...
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality....
Medium - CVE-2024-13525 - The Customer Email Verification for WooCommerce...
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. This makes it...
Medium - CVE-2024-13563 - The Front End Users plugin for WordPress is...
The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password shortcode in all versions up to, and including, 3.2.30 due to...
Medium - CVE-2025-0935 - The Media Library Folders plugin for WordPress...
The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including,...
NA - CVE-2025-22208 - A SQL injection vulnerability in the JS Jobs...
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email'...
NA - CVE-2025-22209 - A SQL injection vulnerability in the JS Jobs...
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the...
Critical - CVE-2024-12562 - The s2Member Pro plugin for WordPress is...
The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the...