Medium - CVE-2025-5814 - The Profiler – What Slowing Down Your WP plugin...
The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsd_plugin_control() function in all...
NA - CVE-2025-5399 - Due to a mistake in libcurl's WebSocket...
Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the...
High - CVE-2025-5303 - The LTL Freight Quotes – Freightview Edition,...
The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress are vulnerable to Stored Cross-Site Scripting...
Medium - CVE-2024-9993 - The Essential Addons for Elementor – Best...
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Medium - CVE-2024-9994 - The Essential Addons for Elementor – Best...
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Medium - CVE-2025-5528 - The Social Sharing Plugin – Sassy Social Share...
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including,...
Medium - CVE-2025-5568 - The WpEvently plugin for WordPress is...
The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output...
Medium - CVE-2025-5836 - A vulnerability was found in Tenda AC9...
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler....
Medium - CVE-2025-5837 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/allemployees.php. The manipulation of...