CVE-2025-7828 – “WordPress WP Filter & Combine RSS Feeds Unauthenticated Data Deletion Vulnerability”
CVE ID : CVE-2025-7828 Published : Aug. 23, 2025, 5:15 a.m. | 22 minutes ago Description : The WP Filter & Combine RSS Feeds plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the post_listing_page() function in all versions up to, and including, 0.4. This makes it possible […]
CVE-2025-7827 – Ni WooCommerce Customer Product Report Unauthorized Data Modification
CVE ID : CVE-2025-7827 Published : Aug. 23, 2025, 5:15 a.m. | 22 minutes ago Description : The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ni_woocpr_action() function in all versions up to, and including, 1.2.4. This makes it possible for […]
CVE-2025-43766 – Liferay Portal/DPX Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-43766 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 23, 2025 Action […]
CVE-2025-7821 – “WordPress WC Plus Favicon Logo Base Unauthorized Modification Vulnerability”
CVE ID : CVE-2025-7821 Published : Aug. 23, 2025, 5:15 a.m. | 22 minutes ago Description : The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘pluswc_logo_favicon_logo_base’ AJAX action in all versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers […]
CVE-2025-7642 – WordPress Simpler Checkout Plugin Authentication Bypass
CVE ID : CVE-2025-7642 Published : Aug. 23, 2025, 5:15 a.m. | 22 minutes ago Description : The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a user’s identity prior to logging them in as an admin through the simplerwc_woocommerce_order_created() […]
CVE-2025-43765 – Liferay Portal Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-43765 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 23, 2025 Action […]
CVE-2025-43764 – Liferay Portal Liferay DXP Regular Expression Denial of Service
Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenticated users with permissions to update Kaleo Workflows to […]
CVE-2025-43767 – Liferay Portal Open Redirect
The following table lists the changes that have been made to the CVE-2025-43767 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 23, 2025 Action […]
CVE-2025-58042 – Apache HTTP Server Cross-Site Request Forgery
The following table lists the changes that have been made to the CVE-2025-58042 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Aug. 23, 2025 Action Type […]
CVE-2025-58043 – Apache HTTP Server Unvalidated User Input
The following table lists the changes that have been made to the CVE-2025-58043 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Aug. 23, 2025 Action Type […]