Recent CVEs (Last 30 days)

3115 CVEs found

CVE-2025-62276
5.5 MEDIUM

The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.1...

Published: 2025-11-01
Products: 23
Vendors:
liferay
CVE-2025-11174
5.3 MEDIUM

The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dl...

Published: 2025-11-01
Products: 0
CVE-2025-11816
5.3 MEDIUM

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...

Published: 2025-11-01
Products: 0

The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14 via the action parameter in one of its shortcodes. This makes it possible for a...

Published: 2025-11-01
Products: 0
CVE-2025-11922
6.4 MEDIUM

The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individual_user' parameter in all versions up to, and including, 3.5.5 due to insuffici...

Published: 2025-11-01
Products: 0
CVE-2025-62275
5.3 MEDIUM

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsuppo...

Published: 2025-11-01
Products: 23
Vendors:
liferay
CVE-2025-11833
9.8 CRITICAL

The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construc...

Published: 2025-11-01
Products: 0
CVE-2025-11928
4.4 MEDIUM

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 12.0.5 due to insufficient input sanitization an...

Published: 2025-11-01
Products: 0
CVE-2025-12367
4.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.3.1. This is due to the plugin not properly verifying that a user is author...

Published: 2025-11-01
Products: 0
CVE-2025-11377
4.3 MEDIUM

The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.92.0 via the 'catlist' shortcode due to insufficient restrictions on which po...

Published: 2025-11-01
Products: 0
CVE-2025-11927
4.4 MEDIUM

The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.14...

Published: 2025-11-01
Products: 0

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization an...

Published: 2025-11-01
Products: 0
CVE-2025-12118
6.4 MEDIUM

The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output es...

Published: 2025-11-01
Products: 0

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating...

Published: 2025-11-01
Products: 0
CVE-2025-11502
6.4 MEDIUM

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all versions up to, and including, 1...

Published: 2025-11-01
Products: 0
CVE-2025-11740
6.5 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied paramet...

Published: 2025-11-01
Products: 0
CVE-2025-11983
4.3 MEDIUM

The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9. This is due to the plugin unconditionally sending Discourse API credentials (Ap...

Published: 2025-11-01
Products: 0
CVE-2025-12038
4.3 MEDIUM

The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the /wp-json/folderly/v1/config/clear-all-data REST API endpoint in all ...

Published: 2025-11-01
Products: 0
CVE-2025-12090
6.4 MEDIUM

The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social URLs in all versions up to, and including, 5.1.2 due t...

Published: 2025-11-01
Products: 0
CVE-2025-12180
4.3 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin storing arbitrary CSS styles submitted via the `qi-bloc...

Published: 2025-11-01
Products: 0