CVE-2025-8149 – aThemes Addons for Elementor Lite <= 1.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

CVE ID : CVE-2025-8149 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Countdown widget in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. […]

CVE-2025-7040 – Cloud SAML SSO <= 1.0.19 – Missing Authorization to Unauthenticated Settings Modification via set_organization_settings Action

CVE ID : CVE-2025-7040 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘set_organization_settings’ action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. The handler reads […]

CVE-2025-58911 – Apache HTTP Server Cross-Site Request Forgery

The following table lists the changes that have been made to the CVE-2025-58911 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Sep. 06, 2025 Action Type […]

CVE-2025-58912 – Apache HTTP Server Cross-Site Request Forgery

The following table lists the changes that have been made to the CVE-2025-58912 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Sep. 06, 2025 Action Type […]

CVE-2025-58905 – Apache HTTP Server Directory Traversal

The following table lists the changes that have been made to the CVE-2025-58905 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Sep. 06, 2025 Action Type […]

CVE-2025-58374 – Roo Code: Auto-approve allows npm install execution of malicious postinstall scripts

The following table lists the changes that have been made to the CVE-2025-58374 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 06, 2025 Action […]