Export limit exceeded: 43172 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (43172 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-45240 1 Qianfox 1 Foxcms 2025-06-12 6.5 Medium
foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.
CVE-2025-45238 1 Qianfox 1 Foxcms 2025-06-12 9.1 Critical
foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.
CVE-2025-45239 1 Qianfox 1 Foxcms 2025-06-12 5.3 Medium
An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.
CVE-2025-4327 1 Mrcms 1 Mrcms 2025-06-12 4.3 Medium
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected.
CVE-2025-4329 1 74cms 1 74cms 2025-06-12 4.3 Medium
A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the function index of the file /index.php/index/download/index. The manipulation of the argument url leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-44073 1 Seacms 1 Seacms 2025-06-12 9.8 Critical
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
CVE-2024-11269 1 Mitchelllevy 1 Ahathat 2025-06-12 7.2 High
The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.
CVE-2024-11267 1 Joomlaserviceprovider 1 Jsp Store Locator 2025-06-12 8.8 High
The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.
CVE-2024-12736 1 Bu 1 Bu Section Editing 2025-06-12 6.1 Medium
The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-11606 1 Tabs Shortcode Project 1 Tabs Shortcode 2025-06-12 5.3 Medium
The Tabs Shortcode WordPress plugin through 2.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2024-8085 1 Solidcode 1 Peoplepond 2025-06-12 6.1 Medium
The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8082 1 Justintadlock 1 Widgets Reset 2025-06-12 4.3 Medium
The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-8050 1 Jfarthing 1 Custom Author Base 2025-06-12 4.3 Medium
The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-8032 1 Ulfbenjaminsson 1 Smooth Gallery Replacement 2025-06-12 6.1 Medium
The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2025-26842 1 Znuny 1 Znuny 2025-06-12 7.5 High
An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the CommunicationLog.
CVE-2024-8031 1 Wpbookingcalendar 1 Secure Downloads 2025-06-12 6.5 Medium
The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.
CVE-2025-26844 1 Znuny 1 Znuny 2025-06-12 9.8 Critical
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
CVE-2022-4363 1 Cedcommerce 2 Wholesale Market, Wholesale Market For Woocommerce 2025-06-12 6.5 Medium
The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack
CVE-2025-43926 1 Znuny 1 Znuny 2025-06-12 6.1 Medium
An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subaction can be used to set user preferences with arbitrary keys. When fetching user data via GetUserData, these keys and values are retrieved and given as a whole to other function calls, which then might use these keys/values to affect permissions or other settings.
CVE-2024-9236 1 Radiustheme 1 Team - Wordpress Team Members Showcase 2025-06-12 4.8 Medium
The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).