CVE-2025-10032 – Campcodes Grocery Sales and Inventory System index.php cross site scripting
The following table lists the changes that have been made to the CVE-2025-10032 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 06, 2025 Action […]
CVE-2025-10031 – Campcodes Grocery Sales and Inventory System ajax.php sql injection
The following table lists the changes that have been made to the CVE-2025-10031 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 06, 2025 Action […]
CVE-2025-10030 – Campcodes Grocery Sales and Inventory System ajax.php sql injection
The following table lists the changes that have been made to the CVE-2025-10030 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 06, 2025 Action […]
CVE-2025-10029 – itsourcecode POS Point of Sale System complex_header_2.php cross site scripting
The following table lists the changes that have been made to the CVE-2025-10029 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 06, 2025 Action […]
CVE-2025-9961 – Authenticated RCE by CWMP binary
The following table lists the changes that have been made to the CVE-2025-9961 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by f23511db-6c3e-4e32-a477-6aa17d310630 Sep. 06, 2025 Action […]
CVE-2025-10028 – itsourcecode POS Point of Sale System 6776.php cross site scripting
The following table lists the changes that have been made to the CVE-2025-10028 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 06, 2025 Action […]
CVE-2025-10046 – ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 – Authenticated (Admin+) SQL Inejction
CVE ID : CVE-2025-10046 Published : Sept. 6, 2025, 6:43 a.m. | 24 minutes ago Description : The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the ‘file_to_delete’ parameter in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack […]
CVE-2025-6757 – Recent Posts Widget Extended
The following table lists the changes that have been made to the CVE-2025-6757 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 06, 2025 Action […]
CVE-2025-9493 – Admin Menu Editor <= 1.14 – Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder Parameter
CVE ID : CVE-2025-9493 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]
CVE-2025-9442 – StreamWeasels Kick Integration <= 1.1.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via vodsChannel Parameter
CVE ID : CVE-2025-9442 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChannel’ parameter in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]