CVE-2025-27523 – Hitachi JP1/IT Desktop Management 2 – Smart Device Manager XXE Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-27523 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 15, 2025 Action […]
CVE-2025-3742 – WordPress Responsive Lightbox & Gallery Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-3742 Published : May 15, 2025, 6:15 a.m. | 1 hour, 23 minutes ago Description : The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored […]
CVE-2025-48027 – pGina HttpAuth DNS Rebinding Vulnerability
The following table lists the changes that have been made to the CVE-2025-48027 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 15, 2025 Action […]
CVE-2024-13914 – “WordPress File Manager Advanced Shortcode Local File Inclusion Vulnerability”
CVE ID : CVE-2024-13914 Published : May 15, 2025, 6:15 a.m. | 1 hour, 23 minutes ago Description : The File Manager Advanced Shortcode WordPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.4 (file-manager-advanced-shortcode) and 2.5.6 (advanced-file-manager-pro-premium), via the ‘file_manager_advanced’ shortcode. This makes it possible for authenticated attackers, […]
CVE-2025-48024 – BlueWave Checkmate Sensitive Data Disclosure
The following table lists the changes that have been made to the CVE-2025-48024 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 15, 2025 Action […]
CVE-2025-3053 – “UiPress Lite WordPress Remote Code Execution Vulnerability”
CVE ID : CVE-2025-3053 Published : May 15, 2025, 5:15 a.m. | 25 minutes ago Description : The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.5.07 via the uip_process_form_input() function. This is due to the function taking […]
CVE-2025-4591 – Weluka Lite Stored Cross-Site Scripting Vulnerability in WordPress
CVE ID : CVE-2025-4591 Published : May 15, 2025, 4:16 a.m. | 1 hour, 25 minutes ago Description : The Weluka Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘weluka-map’ shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This […]
CVE-2025-4589 – WordPress Bon Toolkit Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-4589 Published : May 15, 2025, 4:16 a.m. | 1 hour, 25 minutes ago Description : The Bon Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘bt-map’ shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This […]
CVE-2025-4126 – WordPress EG-Series Plugin Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-4126 Published : May 15, 2025, 4:16 a.m. | 1 hour, 25 minutes ago Description : The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s [series] shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes in the […]
CVE-2025-3917 – “Baidu Station SEO Plugin Arbitrary File Upload Vulnerability”
The following table lists the changes that have been made to the CVE-2025-3917 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 15, 2025 Action […]