A vulnerability classified as critical has been found in Justin Hagstrom AutoIndex PHP Script up to 2.2.0. Affected is an unknown function of the file classes/Url.php. The manipulation of the argument dir leads to improper input validation.
This vulnerability is traded as CVE-2007-5984. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in WonderCMS 3.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Home Page. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-32341. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Boid CMS 2.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Permalink leads to cross site scripting.
This vulnerability is handled as CVE-2024-32342. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Boid CMS 2.1.0. This affects an unknown part. The manipulation of the argument Content leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-32343. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in CMSimple 5.15. This vulnerability affects unknown code of the component Settings Menu. The manipulation of the argument Edit leads to cross site scripting.
This vulnerability was named CVE-2024-32344. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in CMSimple 5.15. This issue affects some unknown processing of the component Language Section. The manipulation of the argument Configuration leads to cross site scripting.
The identification of this vulnerability is CVE-2024-32345. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in Ivanti Connect Secure, Policy Secure and Neurons for ZTA Gateways and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2025-22457. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in CrushFTP up to 10.8.3/11.3.0. This affects the function login_user_pass of the component HTTP Component. The manipulation leads to authentication bypass by primary weakness.
This vulnerability is uniquely identified as CVE-2025-31161. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in edmonparker Read More & Accordion Plugin up to 3.4.5 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function addNewButtons. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-0810. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in KB Support Plugin up to 1.7.4 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /wp-content/uploads/kbs. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-13604. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Email Notifications for Updates Plugin up to 1.1.6 on WordPress. This affects the function awun_import_settings of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-2933. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in Link Library Plugin up to 7.7.3 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-2889. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in AI Content Pipelines Plugin up to 1.6 on WordPress. This issue affects some unknown processing of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-2544. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in MultiVendorX Plugin up to 4.2.19 on WordPress. It has been classified as critical. Affected is the function delete_table_rate_shipping_row. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-2789. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in ZoomSounds Plugin up to 6.91 on WordPress. It has been rated as problematic. Affected by this issue is the function dzsap_delete_notice of the component Setting Handler. The manipulation of the argument seen leads to missing authorization.
This vulnerability is handled as CVE-2024-13776. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in AlThemist Lafka Plugin up to 7.1.0 on WordPress. This affects the function lafka_options_upload of the component Option Update Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-1233. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in ZoomIt ZoomSounds Plugin up to 6.91 on WordPress. This vulnerability affects unknown code of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-0839. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting.
This vulnerability is traded as CVE-2025-3297. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.