NA - CVE-2025-52924 - In One Identity OneLogin before 2025.2.0, the...
In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.
Medium - CVE-2025-7653 - The EPay.bg Payments plugin for WordPress is...
The EPay.bg Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'epay' shortcode in all versions up to, and including, 0.1 due to insufficient...
Medium - CVE-2025-7655 - The Live Stream Badger plugin for WordPress is...
The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' shortcode in all versions up to, and including, 1.4.3 due to...
Medium - CVE-2025-7658 - The Temporarily Hidden Content plugin for...
The Temporarily Hidden Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'temphc-start' shortcode in all versions up to, and including, 1.0.6...
Medium - CVE-2025-7661 - The Partnerský systém Martinus plugin for...
The Partnerský systém Martinus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'martinus' shortcode in all versions up to, and including, 1.7.1 due...
Medium - CVE-2025-7669 - The Avishi WP PayPal Payment Button plugin for...
The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing or incorrect nonce validation...
Critical - CVE-2025-7696 - The Integration for Pipedrive and Contact Form...
The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.3 via...
Critical - CVE-2025-7697 - The Integration for Google Sheets and Contact...
The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via...
NA - CVE-2025-29757 - An incorrect authorisation check in the the...
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her...
Medium - CVE-2025-6720 - The Vchasno Kasa plugin for WordPress is...
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to, and including, 1.0.3. This...