Medium - CVE-2025-2167 - The Event post plugin for WordPress is...
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcodes in all versions up to, and including, 5.9.9 due to...
High - CVE-2025-2257 - The Total Upkeep – WordPress Backup Plugin plus...
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the...
Medium - CVE-2025-1310 - The Jobs for WordPress plugin for WordPress is...
The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11 via the 'job_postings_get_file' parameter. This makes it...
Medium - CVE-2025-1437 - The Advanced iFrame plugin for WordPress is...
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to...
Medium - CVE-2025-1439 - The Advanced iFrame plugin for WordPress is...
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to...
Medium - CVE-2025-1440 - The Advanced iFrame plugin for WordPress is...
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to...
Medium - CVE-2025-1703 - The Ultimate Blocks plugin for WordPress is...
The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 3.2.7 due to insufficient input sanitization...
NA - CVE-2025-1542 - Improper permission control vulnerability in...
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions...
NA - CVE-2025-27551 - DBIx::Class::EncodedColumn use the rand()...
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files...
NA - CVE-2025-27552 - DBIx::Class::EncodedColumn use the rand()...
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files Crypt/Eksblowfish/Bcrypt.pm....