Medium - CVE-2024-13364 - The Raptive Ads plugin for WordPress is...
The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all versions up to, and...
NA - CVE-2025-1007 - In OpenVSX version v0.9.0 to v0.20.0, the...
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The...
NA - CVE-2025-1024 - A vulnerability exists in ChurchCRM 5.13.0 that...
A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php...
NA - CVE-2025-1132 - A time-based blind SQL Injection vulnerability...
A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query...
NA - CVE-2025-1133 - A vulnerability exists in ChurchCRM 5.13.0 and...
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the...
NA - CVE-2025-1134 - A vulnerability exists in ChurchCRM 5.13.0 and...
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the...
NA - CVE-2025-1135 - A vulnerability exists in ChurchCRM 5.13.0. and...
A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the...
High - CVE-2024-13489 - The LTL Freight Quotes – Old Dominion Edition...
The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and...
High - CVE-2024-13478 - The LTL Freight Quotes – TForce Edition plugin...
The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and...