Medium - CVE-2025-2218 - A vulnerability has been found in LoveCards...
A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /api/system/other of the component Setting...
High - CVE-2025-2219 - A vulnerability was found in LoveCards...
A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /api/upload/image. The manipulation of the argument...
Low - CVE-2025-2220 - A vulnerability was found in Odyssey CMS up to...
A vulnerability was found in Odyssey CMS up to 10.34. It has been classified as problematic. Affected is an unknown function of the file /modules/odyssey_contact_form/odyssey_contact_form.php of...
Medium - CVE-2025-1508 - The WP Crowdfunding plugin for WordPress is...
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and including, 2.1.13....
Medium - CVE-2025-2076 - The binlayerpress plugin for WordPress is...
The binlayerpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output...
Medium - CVE-2025-2077 - The Simple Amazon Affiliate plugin for...
The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in all versions up to, and including, 1.0.9 due to insufficient...
Medium - CVE-2025-2078 - The BlogBuzzTime for WP plugin for WordPress is...
The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and...
Medium - CVE-2025-2205 - The GDPR Cookie Compliance – Cookie Banner,...
The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
NA - CVE-2025-24912 - hostapd fails to process crafted RADIUS packets...
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server...
Medium - CVE-2024-13498 - The NEX-Forms – Ultimate Form Builder – Contact...
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads...