Medium - CVE-2025-6787 - The Smart Docs plugin for WordPress is...
The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartdocs_search' shortcode in all versions up to, and including, 1.1.0 due to...
High - CVE-2025-6814 - The Booking X plugin for WordPress is...
The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in versions 1.0 to 1.1.2. This makes it possible for...
Medium - CVE-2025-7046 - The Portfolio for Elementor & Image Gallery |...
The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS Attributes of Plugin's widgets in all versions up...
Low - CVE-2025-7053 - A vulnerability was found in Cockpit up to...
A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument...
Medium - CVE-2025-5372 - A flaw was found in libssh versions built with...
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return...
Medium - CVE-2025-6944 - The Uncode Core plugin for WordPress is...
The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and 'uncode_text_icon' shortcodes in all versions up to,...
Medium - CVE-2024-11937 - The Premium Addons for Elementor plugin for...
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's linkURL in the Mobile Menu element in all versions up to, and including,...