CVE-2025-1135 – ChurchCRM SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-1135 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by b7efe717-a805-47cf-8e9a-921fca0ce0ce Feb. 19, 2025 Action […]
CVE-2025-1134 – ChurchCRM SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-1134 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by b7efe717-a805-47cf-8e9a-921fca0ce0ce Feb. 19, 2025 Action […]
CVE-2025-1133 – ChurchCRM SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-1133 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by b7efe717-a805-47cf-8e9a-921fca0ce0ce Feb. 19, 2025 Action […]
CVE-2025-1132 – ChurchCRM SQL Injection
A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query without proper sanitization, allowing attackers to inject malicious SQL commands. Please note that the vulnerability requires Administrator permissions. This flaw can potentially allow attackers to delay the response, indicating the presence of an […]
CVE-2025-1024 – ChurchCRM Reflected Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-1024 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by b7efe717-a805-47cf-8e9a-921fca0ce0ce Feb. 19, 2025 Action […]
CVE-2025-1007 – OpenVSX Unauthenticated Namespace Details and Logo Manipulation Vulnerability
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.
CVE-2024-13364 – Raptive Ads Plugin WordPress Unauthorized Access Vulnerability
CVE ID : CVE-2024-13364 Published : Feb. 19, 2025, 9:15 a.m. | 30 minutes ago Description : The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to […]
CVE-2024-13363 – WordPress Raptive Ads Reflected Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-13363 Published : Feb. 19, 2025, 9:15 a.m. | 30 minutes ago Description : The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘poc’ parameter in all versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers […]
CVE-2024-13339 – WordPress DeBounce Email Validator CSRF Vulnerability
CVE ID : CVE-2024-13339 Published : Feb. 19, 2025, 9:15 a.m. | 30 minutes ago Description : The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.6. This is due to missing or incorrect nonce validation on the ‘debounce_email_validator’ page. This makes it possible for […]
CVE-2024-13336 – WordPress Disable Auto Updates CSRF
CVE ID : CVE-2024-13336 Published : Feb. 19, 2025, 9:15 a.m. | 30 minutes ago Description : The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the ‘disable-auto-updates’ page. This makes it possible for […]