Critical - CVE-2025-1771 - The Traveler theme for WordPress is vulnerable...
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style'...
Medium - CVE-2025-1773 - The Traveler theme for WordPress is vulnerable...
The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and...
NA - CVE-2025-30066 - tj-actions changed-files before 46 allows...
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were...
Medium - CVE-2019-25222 - The Thumbnail carousel slider plugin for...
The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the...
Low - CVE-2025-2157 - A flaw was found in Foreman/Red Hat Satellite....
A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such...
High - CVE-2025-2325 - The WP Test Email plugin for WordPress is...
The WP Test Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output...
Medium - CVE-2025-1057 - A flaw was found in Keylime, a remote...
A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous...
Medium - CVE-2025-1530 - The Tripetto plugin for WordPress is vulnerable...
The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.9. This is due to missing nonce validation. This makes it possible for...
Medium - CVE-2025-2025 - The GiveWP – Donation Plugin and Fundraising...
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the give_reports_earnings() function in...
Medium - CVE-2025-2321 - A vulnerability was found in 274056675...
A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this issue is some unknown functionality of the file...