Aggregator
漏洞预警 | React/Next.js组件RCE漏洞(CVE-2025-55182)详情分析-【附验证环境】
1 month 2 weeks ago
【安全圈】“淘宝崩了”“支付宝崩了”“闲鱼崩了”冲上热搜,客服回应
1 month 2 weeks ago
《网络安全标识管理办法》公开征求意见
CVE-2025-62223 | Microsoft Edge up to 142.0.3595.53 on iOS clickjacking (EUVD-2025-201318)
1 month 2 weeks ago
A vulnerability was found in Microsoft Edge on iOS. It has been classified as problematic. Affected is an unknown function. This manipulation causes clickjacking.
This vulnerability is registered as CVE-2025-62223. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-13621 | Dream Gallery Plugin up to 1.0 on WordPress Setting dreampluginsmain cross-site request forgery
1 month 2 weeks ago
A vulnerability was found in Dream Gallery Plugin up to 1.0 on WordPress and classified as problematic. This impacts the function dreampluginsmain of the component Setting Handler. The manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2025-13621. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-13682 | Trail Manager Plugin up to 1.0.0 on WordPress Setting cross site scripting
1 month 2 weeks ago
A vulnerability has been found in Trail Manager Plugin up to 1.0.0 on WordPress and classified as problematic. This affects an unknown function of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2025-13682. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-13614 | Cool Tag Cloud Plugin up to 2.29 on WordPress Shortcode cool_tag_cloud cross site scripting
1 month 2 weeks ago
A vulnerability, which was classified as problematic, was found in Cool Tag Cloud Plugin up to 2.29 on WordPress. The impacted element is the function cool_tag_cloud of the component Shortcode Handler. Executing manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2025-13614. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-13678 | Thai Lottery Widget Plugin up to 2.5 on WordPress width/height cross site scripting
1 month 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Thai Lottery Widget Plugin up to 2.5 on WordPress. The affected element is an unknown function. Performing manipulation of the argument width/height results in cross site scripting.
This vulnerability is identified as CVE-2025-13678. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-12879 | User Generator and Importer Plugin up to 1.2.2 on WordPress cross-site request forgery
1 month 2 weeks ago
A vulnerability classified as problematic was found in User Generator and Importer Plugin up to 1.2.2 on WordPress. Impacted is an unknown function. Such manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2025-12879. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-13739 | CryptX Plugin up to 4.0.4 on WordPress Shortcode cryptx cross site scripting
1 month 2 weeks ago
A vulnerability classified as problematic has been found in CryptX Plugin up to 4.0.4 on WordPress. This issue affects the function cryptx of the component Shortcode Handler. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-13739. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-13684 | ARK Related Posts Plugin up to 2.19 on WordPress Setting ark_rp_options_page cross-site request forgery
1 month 2 weeks ago
A vulnerability described as problematic has been identified in ARK Related Posts Plugin up to 2.19 on WordPress. This vulnerability affects the function ark_rp_options_page of the component Setting Handler. The manipulation results in cross-site request forgery.
This vulnerability was named CVE-2025-13684. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-10055 | Time Sheets Plugin up to 2.1.3 on WordPress cross-site request forgery
1 month 2 weeks ago
A vulnerability marked as problematic has been reported in Time Sheets Plugin up to 2.1.3 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-10055. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-12368 | Sermon Manager Plugin up to 2.30.0 on WordPress Shortcode sermon-views cross site scripting
1 month 2 weeks ago
A vulnerability labeled as problematic has been found in Sermon Manager Plugin up to 2.30.0 on WordPress. Affected by this issue is the function sermon-views of the component Shortcode Handler. Executing manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2025-12368. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2025-12373 | Torod Plugin up to 1.9 on WordPress Setting save_settings cross-site request forgery
1 month 2 weeks ago
A vulnerability identified as problematic has been detected in Torod Plugin up to 1.9 on WordPress. Affected by this vulnerability is the function save_settings of the component Setting Handler. Performing manipulation results in cross-site request forgery.
This vulnerability is known as CVE-2025-12373. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-12186 | Weekly Planner Plugin up to 1.0 on WordPress Setting cross site scripting
1 month 2 weeks ago
A vulnerability categorized as problematic has been discovered in Weekly Planner Plugin up to 1.0 on WordPress. Affected is an unknown function of the component Setting Handler. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-12186. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-12124 | FitVids Plugin up to 4.0.1 on WordPress Setting cross site scripting
1 month 2 weeks ago
A vulnerability was found in FitVids Plugin up to 4.0.1 on WordPress. It has been rated as problematic. This impacts an unknown function of the component Setting Handler. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-12124. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-13144 | ContentStudio Plugin up to 1.3.7 on WordPress Setting add_cstu_settings cross-site request forgery
1 month 2 weeks ago
A vulnerability was found in ContentStudio Plugin up to 1.3.7 on WordPress. It has been declared as problematic. This affects the function add_cstu_settings of the component Setting Handler. The manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2025-13144. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-13620 | WP Social Login and Register Social Counter Plugin REST Endpoint wslu/v1/check_cache/ authorization
1 month 2 weeks ago
A vulnerability was found in WP Social Login and Register Social Counter Plugin up to 3.1.3 on WordPress. It has been classified as critical. The impacted element is an unknown function of the file wslu/v1/check_cache/ of the component REST Endpoint. The manipulation leads to missing authorization.
This vulnerability is documented as CVE-2025-13620. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-13860 | Easy Jump Links Menus Plugin up to 1.0.0 on WordPress Shortcode h_tags cross site scripting
1 month 2 weeks ago
A vulnerability was found in Easy Jump Links Menus Plugin up to 1.0.0 on WordPress and classified as problematic. The affected element is an unknown function of the component Shortcode Handler. Executing manipulation of the argument h_tags can lead to cross site scripting.
This vulnerability is registered as CVE-2025-13860. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-12130 | WC Vendors Plugin up to 2.6.4 on WordPress delete cross-site request forgery
1 month 2 weeks ago
A vulnerability has been found in WC Vendors Plugin up to 2.6.4 on WordPress and classified as problematic. Impacted is an unknown function of the file /vendor_dashboard/product/delete/. Performing manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2025-12130. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com