Aggregator
CVE-2025-26971 | ays-pro Poll Maker Plugin up to 5.6.5 on WordPress sql injection
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in ays-pro Poll Maker Plugin up to 5.6.5 on WordPress. Affected is an unknown function. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2025-26971. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-26957 | Deetronix Affiliate Coupons Plugin up to 1.7.3 on WordPress filename control
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Deetronix Affiliate Coupons Plugin up to 1.7.3 on WordPress. This issue affects some unknown processing. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2025-26957. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-26964 | Themewinter Eventin Plugin up to 4.0.20 on WordPress filename control
9 months 2 weeks ago
A vulnerability classified as problematic was found in Themewinter Eventin Plugin up to 4.0.20 on WordPress. This vulnerability affects unknown code. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability was named CVE-2025-26964. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-26932 | QuantumCloud ChatBot Plugin up to 6.3.5 on WordPress filename control
9 months 2 weeks ago
A vulnerability classified as problematic has been found in QuantumCloud ChatBot Plugin up to 6.3.5 on WordPress. This affects an unknown part. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is uniquely identified as CVE-2025-26932. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-26979 | FunnelKit Funnel Builder Plugin up to 3.9.0 on WordPress filename control
9 months 2 weeks ago
A vulnerability was found in FunnelKit Funnel Builder Plugin up to 3.9.0 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is known as CVE-2025-26979. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-26905 | Estatik Plugin up to 4.1.9 on WordPress path traversal
9 months 2 weeks ago
A vulnerability was found in Estatik Plugin up to 4.1.9 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2025-26905. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-1522 | PostHog database_schema server-side request forgery
9 months 2 weeks ago
A vulnerability was found in PostHog. It has been classified as critical. Affected is the function database_schema. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2025-1522. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-1521 | PostHog slack_incoming_webhook server-side request forgery
9 months 2 weeks ago
A vulnerability was found in PostHog and classified as critical. This issue affects the function slack_incoming_webhook. The manipulation leads to server-side request forgery.
The identification of this vulnerability is CVE-2025-1521. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-26881 | bPlugins Sticky Content Plugin up to 1.0.1 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability has been found in bPlugins Sticky Content Plugin up to 1.0.1 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-26881. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-26876 | CodeManas Search with Typesense Plugin up to 2.0.8 on WordPress path traversal
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in CodeManas Search with Typesense Plugin up to 2.0.8 on WordPress. This affects an unknown part. The manipulation leads to path traversal: '.../...//'.
This vulnerability is uniquely identified as CVE-2025-26876. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-26751 | Fahad Mahmood Alphabetic Pagination Plugin up to 3.2.1 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability classified as problematic was found in Fahad Mahmood Alphabetic Pagination Plugin up to 3.2.1 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-26751. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-26877 | Rustaurius Front End Users Plugin up to 3.2.30 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Rustaurius Front End Users Plugin up to 3.2.30 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-26877. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-54444 | Elementor Website Builder Plugin up to 3.25.10 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability classified as problematic has been found in Elementor Website Builder Plugin up to 3.25.10 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-54444. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-26868 | fastflow Fast Flow Plugin up to 1.2.16 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability was found in fastflow Fast Flow Plugin up to 1.2.16 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-26868. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-26878 | patternsinthecloud Autoship Cloud for WooCommerce Subscription Products Plugin cross site scripting
9 months 2 weeks ago
A vulnerability was found in patternsinthecloud Autoship Cloud for WooCommerce Subscription Products Plugin up to 2.8.0.1 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-26878. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2015-1366 | Pixabay Images up to 2.2 pixabay-images.php image_user cross site scripting (ID 130017 / EDB-35846)
9 months 2 weeks ago
A vulnerability classified as problematic has been found in Pixabay Images up to 2.2. Affected is an unknown function of the file pixabay-images.php. The manipulation of the argument image_user leads to cross site scripting.
This vulnerability is traded as CVE-2015-1366. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42003 | Oracle Enterprise Manager Base Platform 13.5.0.0 Agent Next Gen denial of service (Nessus ID 216682)
9 months 2 weeks ago
A vulnerability was found in Oracle Enterprise Manager Base Platform 13.5.0.0. It has been rated as critical. This issue affects some unknown processing of the component Agent Next Gen. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2022-42003. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-42003 | Oracle Enterprise Manager Base Platform 13.5.0.0 Extensibility Framework denial of service (Nessus ID 216682)
9 months 2 weeks ago
A vulnerability classified as critical has been found in Oracle Enterprise Manager Base Platform 13.5.0.0. Affected is an unknown function of the component Extensibility Framework. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2022-42003. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-42003 | Oracle Enterprise Manager for Virtualization 13.5.0.0 Plug-In Lifecycle denial of service (Nessus ID 216682)
9 months 2 weeks ago
A vulnerability was found in Oracle Enterprise Manager for Virtualization 13.5.0.0 and classified as critical. This issue affects some unknown processing of the component Plug-In Lifecycle. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2022-42003. The attack may be initiated remotely. There is no exploit available.
vuldb.com