NA - CVE-2025-0205 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /details2.php. The manipulation of the argument id leads to...
Medium - CVE-2024-12221 - The Turnkey bbPress by WeaverTheme plugin for...
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in all versions up to, and including, 1.6.3 due to insufficient...
Medium - CVE-2024-12195 - The WP Project Manager – Task, team, and...
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id'...
Medium - CVE-2024-12279 - The WP Social AutoConnect plugin for WordPress...
The WP Social AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.2. This is due to missing or incorrect nonce validation on a...
Medium - CVE-2024-12475 - The WP Multi Store Locator plugin for WordPress...
The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping....
NA - CVE-2025-0206 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation...
NA - CVE-2025-0207 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/login.php. The...
NA - CVE-2025-0208 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /summary.php. The manipulation of the argument tid...
High - CVE-2024-10957 - The UpdraftPlus: WP Backup & Migration Plugin...
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.24.11 via deserialization of untrusted input in the...
NA - CVE-2025-0210 - A vulnerability has been found in Campcodes...
A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file...