CVE-2025-47785 – Emlog SQL Injection and Remote Code Execution
Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this will cause SQL injection to occur when the registered site is enabled, resulting in the injection of […]
CVE-2025-47784 – Emlog Deserialization Vulnerability
The following table lists the changes that have been made to the CVE-2025-47784 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 15, 2025 Action […]
CVE-2025-47161 – Microsoft Defender for Endpoint Elevation of Privilege Vulnerability
The following table lists the changes that have been made to the CVE-2025-47161 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 15, 2025 Action […]
CVE-2025-46834 – Alchemy’s Modular Account Allowlist Bypass Vulnerability (Authorization Issue)
The following table lists the changes that have been made to the CVE-2025-46834 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 15, 2025 Action […]
CVE-2025-2248 – “WordPress WP-PManager SQL Injection Vulnerability”
CVE ID : CVE-2025-2248 Published : May 15, 2025, 8:16 p.m. | 25 minutes ago Description : The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks Severity: 0.0 | NA Visit the link for more details, such as […]
CVE-2025-2203 – FunnelKit WordPress SQL Injection Vulnerability
CVE ID : CVE-2025-2203 Published : May 15, 2025, 8:16 p.m. | 25 minutes ago Description : The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks Severity: 0.0 | NA Visit the link for more details, such as […]
CVE-2025-2247 – WordPress WP-PManager CSRF
CVE ID : CVE-2025-2247 Published : May 15, 2025, 8:16 p.m. | 25 minutes ago Description : The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack Severity: 0.0 | NA Visit the […]
CVE-2025-1454 – Ninja Pages Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-1454 Published : May 15, 2025, 8:16 p.m. | 25 minutes ago Description : The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for […]
CVE-2025-1303 – WordPress Plugin Oficial Reflected Cross-Site Scripting
CVE ID : CVE-2025-1303 Published : May 15, 2025, 8:16 p.m. | 25 minutes ago Description : The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users. Severity: 0.0 | NA […]
CVE-2025-1289 – WordPress Oficial Plugin Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-1289 Published : May 15, 2025, 8:16 p.m. | 25 minutes ago Description : The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for […]