NA - CVE-2025-25224 - The LuxCal Web Calendar prior to 5.3.3M (MySQL...
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited,...
Medium - CVE-2024-13741 - The ProfileGrid – User Profiles, Groups and...
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the...
Medium - CVE-2024-13740 - The ProfileGrid – User Profiles, Groups and...
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the...
NA - CVE-2025-1390 - The PAM module pam_cap.so of libcap...
The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This...
NA - CVE-2024-12314 - The Rapid Cache plugin for WordPress is...
The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This is due to plugin storing HTTP headers in the cached data. This makes it...
Medium - CVE-2024-12525 - The Easy MLS Listings Import plugin for...
The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-featured-listings' shortcode in all versions up to, and...
Medium - CVE-2024-12813 - The Open Hours – Easy Opening Hours plugin for...
The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'open-hours-current-status' shortcode in all versions up to,...
Medium - CVE-2024-13464 - The Library Bookshelves plugin for WordPress is...
The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' shortcode in all versions up to, and including, 5.9 due to...
Medium - CVE-2024-13501 - The WP-FormAssembly plugin for WordPress is...
The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due to...
Medium - CVE-2024-13522 - The magayo Lottery Results plugin for WordPress...
The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12. This is due to missing or incorrect nonce validation on the...