Critical - CVE-2012-10020 - The FoxyPress plugin for WordPress is...
The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions up to, and including, 0.4.2.1. This makes it...
Critical - CVE-2015-10137 - The Website Contact Form With File Upload...
The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up...
Medium - CVE-2025-5240 - The CRM and Lead Management by vcita plugin for...
The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 2.7.5 due to insufficient input...
Medium - CVE-2025-6831 - The User Registration plugin for WordPress is...
The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient...
Low - CVE-2025-7949 - A vulnerability was found in Sanluan PublicCMS...
A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file...