NA - CVE-2025-54622 - Binding authentication bypass vulnerability in...
Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Medium - CVE-2025-6256 - The Flex Guten plugin for WordPress is...
The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ parameter in all versions up to, and including, 1.2.5 due to insufficient input...
Medium - CVE-2025-6259 - The esri-map-view plugin for WordPress is...
The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view shortcode in all versions up to, and including, 1.2.3 due to insufficient...
Medium - CVE-2025-6690 - The WP Tournament Registration plugin for...
The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 due to insufficient input...
Medium - CVE-2025-6986 - The FileBird – WordPress Media Library Folders...
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 6.4.8...
High - CVE-2025-7036 - The CleverReach® WP plugin for WordPress is...
The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user...
Medium - CVE-2025-7502 - The WPBakery Page Builder for WordPress plugin...
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input...