Medium - CVE-2024-13713 - The WPExperts Square For GiveWP plugin for...
The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 due to insufficient escaping on...
Medium - CVE-2024-13846 - The Indeed Ultimate Learning Pro plugin for...
The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insufficient escaping on...
Medium - CVE-2024-13900 - The Head, Footer and Post Injections plugin for...
The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with...
NA - CVE-2024-9150 - Report generation functionality in Wyn...
Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to...
Medium - CVE-2025-1402 - The Event Tickets and Registration plugin for...
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions...
Medium - CVE-2025-1489 - The WP-Appbox plugin for WordPress is...
The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all versions up to, and including, 4.5.4 due to insufficient input...
High - CVE-2025-1535 - A vulnerability was found in Baiyi Cloud Asset...
A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. It has been classified as critical. This affects an unknown part of the file /wuser/admin.ticket.close.php. The...
NA - CVE-2020-6158 - Opera Mini for Android before version 52.2 is...
Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different...
Medium - CVE-2024-10222 - The SVG Support plugin for WordPress is...
The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output...