CVE-2025-9126 – Smart Table Builder <= 1.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
CVE ID : CVE-2025-9126 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]
CVE-2025-8722 – Content Views <= 4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Grid and List Widgets
CVE ID : CVE-2025-8722 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Grid and List widgets in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping on user supplied attributes. […]
CVE-2025-8564 – SKT Addons for Elementor <= 3.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
CVE ID : CVE-2025-8564 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes […]
CVE-2025-8149 – aThemes Addons for Elementor Lite <= 1.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
CVE ID : CVE-2025-8149 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Countdown widget in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. […]
CVE-2025-7045 – Cloud SAML SSO <= 1.0.19 – Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action
CVE ID : CVE-2025-7045 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. This makes it possible […]
CVE-2025-7040 – Cloud SAML SSO <= 1.0.19 – Missing Authorization to Unauthenticated Settings Modification via set_organization_settings Action
CVE ID : CVE-2025-7040 Published : Sept. 6, 2025, 4:16 a.m. | 24 minutes ago Description : The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘set_organization_settings’ action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. The handler reads […]
CVE-2025-58911 – Apache HTTP Server Cross-Site Request Forgery
The following table lists the changes that have been made to the CVE-2025-58911 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Sep. 06, 2025 Action Type […]
CVE-2025-58912 – Apache HTTP Server Cross-Site Request Forgery
The following table lists the changes that have been made to the CVE-2025-58912 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Sep. 06, 2025 Action Type […]
CVE-2025-58905 – Apache HTTP Server Directory Traversal
The following table lists the changes that have been made to the CVE-2025-58905 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Sep. 06, 2025 Action Type […]
CVE-2025-58374 – Roo Code: Auto-approve allows npm install execution of malicious postinstall scripts
The following table lists the changes that have been made to the CVE-2025-58374 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 06, 2025 Action […]