CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10684
4.3 MEDIUM

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as …

Dec 12, 2025
CVE-2025-66492
8.2 HIGH

Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0-alpha.1 through 7.4.8 and 7.5.0 through 7.5.1 are …

Dec 12, 2025
CVE-2025-66284
5.4 MEDIUM

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in …

Dec 12, 2025
CVE-2025-65120
6.1 MEDIUM

Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. If a …

Dec 12, 2025
CVE-2025-64781
4.7 MEDIUM

In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External page display restriction" is set to …

Dec 12, 2025
CVE-2025-62192
5.4 MEDIUM

SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If exploited, information …

Dec 12, 2025
CVE-2025-61987
5.3 MEDIUM

GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a …

Dec 12, 2025
CVE-2025-61950
4.3 MEDIUM

In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. With some crafted request, a …

Dec 12, 2025
CVE-2025-58576
4.3 MEDIUM

Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a …

Dec 12, 2025
CVE-2025-57883
6.1 MEDIUM

Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a …

Dec 12, 2025
CVE-2025-54407
6.1 MEDIUM

Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a …

Dec 12, 2025
CVE-2025-53523
5.4 MEDIUM

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. A logged-in …

Dec 12, 2025
CVE-2025-14467
4.4 MEDIUM

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.4. This is due to …

Dec 12, 2025
CVE-2025-14393
6.4 MEDIUM

The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' parameter in all versions up to, and …

Dec 12, 2025
CVE-2025-14392
4.3 MEDIUM

The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_theme_admin, display_method_admin, and …

Dec 12, 2025
CVE-2025-14391
4.3 MEDIUM

The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing …

Dec 12, 2025
CVE-2025-14354
4.3 MEDIUM

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This …

Dec 12, 2025
CVE-2025-14344
9.8 CRITICAL

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function …

Dec 12, 2025
CVE-2025-14170
4.3 MEDIUM

The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 0.2. This is due to missing authorization …

Dec 12, 2025
CVE-2025-14166
5.3 MEDIUM

The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.0. This is due to the plugin …

Dec 12, 2025
CVE-2025-14165
4.3 MEDIUM

The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9. This is due to …

Dec 12, 2025
CVE-2025-14162
4.3 MEDIUM

The BMLT WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.11.4. This is due to missing …

Dec 12, 2025
CVE-2025-14161
4.3 MEDIUM

The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing …

Dec 12, 2025
CVE-2025-14160
4.3 MEDIUM

The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to …

Dec 12, 2025
CVE-2025-14158
4.3 MEDIUM

The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing …

Dec 12, 2025
CVE-2025-14143
6.4 MEDIUM

The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' parameter of the ayo_action shortcode in all versions up to, …

Dec 12, 2025
CVE-2025-14138
6.1 MEDIUM

The WPLG Default Mail From plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, …

Dec 12, 2025
CVE-2025-14137
6.1 MEDIUM

The Simple AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.2.10 …

Dec 12, 2025
CVE-2025-14132
6.1 MEDIUM

The Category Dropdown List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0 …

Dec 12, 2025
CVE-2025-14129
6.1 MEDIUM

The Like DisLike Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0.1 …

Dec 12, 2025
CVE-2025-14125
6.1 MEDIUM

The Complag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0.2 due to …

Dec 12, 2025
CVE-2025-14119
6.4 MEDIUM

The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'atvc_video_play' shortcode in …

Dec 12, 2025
CVE-2025-14064
5.4 MEDIUM

The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX endpoints in …

Dec 12, 2025
CVE-2025-14062
4.3 MEDIUM

The Animated Pixel Marquee Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery via the 'marquee' parameter in all versions up to, and including, …

Dec 12, 2025
CVE-2025-14048
4.4 MEDIUM

The SimplyConvert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'simplyconvert_hash' option in all versions up to, and including, 1.0 due to …

Dec 12, 2025
CVE-2025-14045
4.3 MEDIUM

The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due to a missing capability check on the url_media_uploader_url_upload_ajax_handler() function in …

Dec 12, 2025
CVE-2025-14044
8.1 HIGH

The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.3 via deserialization of untrusted …

Dec 12, 2025
CVE-2025-14035
4.4 MEDIUM

The DebateMaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color options in the plugin settings in all versions up to, and …

Dec 12, 2025
CVE-2025-14032
6.4 MEDIUM

The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'bold_timeline_group' shortcode in all versions up …

Dec 12, 2025
CVE-2025-13989
6.4 MEDIUM

The WP Dropzone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callback' shortcode attribute in all versions up to, and including, 1.1.1. …

Dec 12, 2025
CVE-2025-13988
6.1 MEDIUM

The 评论小秘书 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.3.2. This is …

Dec 12, 2025
CVE-2025-13987
4.3 MEDIUM

The Purchase and Expense Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due …

Dec 12, 2025
CVE-2025-13975
4.4 MEDIUM

The Contact Form 7 with ChatWork plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_token' and 'roomid' settings in all versions up …

Dec 12, 2025
CVE-2025-13972
4.9 MEDIUM

The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' parameter in all versions up to, and including, 3.16.0. This is …

Dec 12, 2025
CVE-2025-13971
4.4 MEDIUM

The TWW Protein Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Header' setting in all versions up to, and including, 1.0.24 …

Dec 12, 2025
CVE-2025-13969
6.4 MEDIUM

The Reviews Sorted plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'space' parameter of the [reviews-slider] shortcode in all versions up to, …

Dec 12, 2025
CVE-2025-13966
6.4 MEDIUM

The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' parameter of the [paypal-shortcode] shortcode in all versions up …

Dec 12, 2025
CVE-2025-13963
6.4 MEDIUM

The FX Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fxcc_convert' shortcode in all versions up to, and including, …

Dec 12, 2025
CVE-2025-13962
6.4 MEDIUM

The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shortcode in all versions up to, and including, 1.5 …

Dec 12, 2025
CVE-2025-13961
6.4 MEDIUM

The Data Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'visualize' shortcode in all versions up to, and including, 1.1 …

Dec 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.