NA - CVE-2025-0347 - A vulnerability was found in code-projects...
A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php of the component Login....
NA - CVE-2025-0348 - A vulnerability was found in CampCodes DepEd...
A vulnerability was found in CampCodes DepEd Equipment Inventory System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /data/add_employee.php. The...
Medium - CVE-2024-11328 - The CLUEVO LMS, E-Learning Platform plugin for...
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL...
Critical - CVE-2024-11642 - The Post Grid Master – Custom Post Types,...
The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File...
Medium - CVE-2024-11686 - The WhatsApp ?? click to chat plugin for...
The WhatsApp ?? click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and including, 3.0.4 due to...
Medium - CVE-2024-11815 - The Pósturinn\'s Shipping with WooCommerce...
The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the printed_marked and nonprinted_marked parameters in all versions up to,...
Medium - CVE-2024-11907 - The Skyword API Plugin plugin for WordPress is...
The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_iframe' shortcode in all versions up to, and including, 2.5.2 due...
Medium - CVE-2024-11929 - The Responsive FlipBook Plugin Wordpress plugin...
The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp_save_settings() functionin all versions up to, and including, 2.5.0 due to...
Medium - CVE-2024-12067 - The WP Travel – Ultimate Travel Booking System,...
The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the 'booking_itinerary' parameter of the...
Medium - CVE-2024-12122 - The ResAds plugin for WordPress is vulnerable...
The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.6 due to insufficient input sanitization and output...