Medium - CVE-2025-0865 - The WP Media Category Management plugin for...
The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-13231 - The WordPress Portfolio Builder – Portfolio...
The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_video' function...
Medium - CVE-2024-13336 - The Disable Auto Updates plugin for WordPress...
The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-13339 - The DeBounce Email Validator plugin for...
The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.6. This is due to missing or incorrect nonce validation on...
Medium - CVE-2024-13363 - The Raptive Ads plugin for WordPress is...
The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all versions up to, and including, 3.6.3 due to insufficient input...
Medium - CVE-2024-13364 - The Raptive Ads plugin for WordPress is...
The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all versions up to, and...
NA - CVE-2025-1007 - In OpenVSX version v0.9.0 to v0.20.0, the...
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The...
NA - CVE-2025-1024 - A vulnerability exists in ChurchCRM 5.13.0 that...
A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php...
NA - CVE-2025-1132 - A time-based blind SQL Injection vulnerability...
A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query...
NA - CVE-2025-1133 - A vulnerability exists in ChurchCRM 5.13.0 and...
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the...