NA - CVE-2025-31710 - In engineermode service, there is a possible...
In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
NA - CVE-2025-31711 - In cplog service, there is a possible system...
In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional execution privileges needed.
NA - CVE-2025-31712 - In cplog service, there is a possible out of...
In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed.
NA - CVE-2025-3584 - The Newsletter WordPress plugin before 8.8.2...
The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site...
NA - CVE-2025-3662 - The FancyBox for WordPress plugin before 3.3.6...
The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+...
NA - CVE-2025-4567 - The Post Slider and Post Carousel with Post...
The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options before outputting them back in a...