Medium - CVE-2025-5563 - The WP-Addpub plugin for WordPress is...
The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, and including, 1.2.8 due to insufficient escaping on the user...
Medium - CVE-2025-5565 - The Hide It plugin for WordPress is vulnerable...
The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all versions up to, and including, 1.0.1 due to insufficient...
Medium - CVE-2025-5586 - The WordPress Ajax Load More and Infinite...
The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.0 due to...
Medium - CVE-2025-5686 - The Paged Gallery plugin for WordPress is...
The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 0.7 due to insufficient...
Medium - CVE-2025-5699 - The Developer Formatter plugin for WordPress is...
The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2015.0.2.1 due to insufficient input sanitization...
Medium - CVE-2025-5703 - The StageShow plugin for WordPress is...
The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all versions up to, and including, 10.0.3 due to insufficient input sanitization and...
Low - CVE-2025-5727 - A vulnerability classified as problematic has...
A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/announcement of the...
Medium - CVE-2025-5728 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code of the file /manage_website.php. The...
Medium - CVE-2025-5729 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in code-projects Health Center Patient Record Management System 1.0. Affected is an unknown function of the file /birthing_record.php....
NA - CVE-2025-3321 - A predefined administrative account is not...
A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users on the server.