CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Mar 8, 2025

Product Input Fields for WooCommerce Unauthenticated File Upload Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the Product Input Fields for WooCommerce plugin for WordPress, affecting all versions through 1.12.0. The issue arises from inadequate file type validation in the 'add_product_input_fields_to_order_item_meta()' function. This vulnerability could enable unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution. By default, the plugin is only susceptible to double extension file upload attacks, unless an administrator leaves the accepted file extensions field blank, which could allow .php file uploads.

3.6
Mar 8, 2025

The Plus Addons for Elementor Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in The Plus Addons for Elementor WordPress plugin, specifically in versions through 6.2.2. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts into pages via the Countdown, Syntax Highlighter, and Page Scroll widgets. The injected scripts are executed when users access the affected pages, exploiting insufficient input sanitization and output escaping.

4.7
Mar 8, 2025

Javo Core WordPress Plugin Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in the Javo Core plugin for WordPress, affecting all versions through 3.0.0.080. The vulnerability arises because the plugin allows users registering new accounts to choose their own roles. This functionality can be exploited by unauthenticated attackers to create accounts with administrative privileges.

2.6
Mar 8, 2025

Aiomatic WordPress Plugin Arbitrary File Upload Vulnerability Allowing Remote Code Execution

A vulnerability exists in the Aiomatic WordPress plugin, specifically in the 'aiomatic_generate_featured_image' function, all versions through 2.3.8. The issue arises from inadequate file type validation, allowing authenticated users with Contributor-level access or higher to upload arbitrary files to the server. This could potentially lead to remote code execution.

2.3
Mar 8, 2025

Aiomatic WordPress Plugin Missing Authorization Vulnerability Allows Unauthorized Data Modification

A vulnerability exists in the Aiomatic WordPress plugin, specifically in the Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit version 2.3.6 and prior. The issue stems from inadequate capability checks on several functions, enabling authenticated attackers with Subscriber-level access or higher to unauthorized access, modification, and deletion of various data. Exploitation allows these attackers to update and delete posts, manage batches, access and delete uploaded files, remove personas, forms, and templates, and clear logs. This vulnerability was partially addressed in version 2.3.5.

2.1
Mar 8, 2025

All-in-One Addons for Elementor WidgetKit Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the All-in-One Addons for Elementor – WidgetKit plugin for WordPress. This issue affects all versions through 2.5.4 and is located in the elements/advanced-tab/template/view.php file. The vulnerability allows authenticated attackers with Contributor-level access and above to access sensitive data from private, pending, and draft templates.

4.5
Mar 8, 2025

SMTP by BestWebSoft WordPress Plugin Arbitrary File Upload Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the SMTP by BestWebSoft plugin for WordPress, affecting all versions through 1.1.9. The issue arises from inadequate file type validation in the 'save_options' function, which enables authenticated attackers with Administrator-level access and above to upload arbitrary files to the server. This vulnerability could potentially lead to remote code execution.

4.5
Mar 8, 2025

miniOrange Social Login and Register Pro Addon Authentication Bypass Vulnerability

A vulnerability allowing authentication bypass has been identified in the miniOrange Social Login and Register Pro Addon for WordPress, in all versions through 200.3.9. The issue arises from inadequate verification of users associated with social login tokens, enabling unauthenticated attackers to log in as any existing user, including administrators. This exploitation is possible if the attacker knows the username and the user lacks an existing account with the service providing the token.

4.0
Mar 8, 2025

Post SMTP WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Post SMTP plugin for WordPress, affecting all versions through 3.1.2. The issue arises from inadequate escaping of user-supplied data in the 'columns' parameter, allowing authenticated attackers with Administrator-level access to manipulate SQL queries. This exploitation could lead to unauthorized access to sensitive database information.

2.6
Mar 8, 2025

Email Keep WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Email Keep WordPress plugin, affecting versions through 1.1. The plugin lacks proper CSRF protection when updating settings, which could enable attackers to manipulate settings of a logged-in admin.

3.3
Mar 8, 2025

Email Keep WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Email Keep WordPress plugin, affecting versions through 1.1. The issue arises because the plugin fails to properly sanitize and escape a parameter before displaying it on the page. This vulnerability could be exploited against users with high privileges, such as administrators.

3.4
Mar 8, 2025

FooGallery Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the FooGallery WordPress plugin, specifically in versions through 2.4.29. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with gallery and album creator roles to inject arbitrary scripts. These scripts are executed when a user accesses the affected page.

4.4
Mar 8, 2025

FooGallery WordPress Plugin Insecure Direct Object Reference Vulnerability Allowing Arbitrary Post Updates

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the FooGallery WordPress plugin, specifically in versions through 2.4.29. The issue arises in the foogallery_attachment_modal_save AJAX action, where validation is lacking on a user-controlled key (img_id). This vulnerability enables authenticated attackers with the appropriate access level to modify arbitrary post and page content. However, for this vulnerability to have a significant impact, the Gallery Creator Role setting must be below 'Editor'.

4.3
Mar 8, 2025

Print Invoice & Delivery Notes for WooCommerce Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure exists in the Print Invoice & Delivery Notes for WooCommerce plugin, affecting all versions through 5.4.1. The issue arises from an unprotected 'wcdn/invoice' directory, where sensitive data, including invoice files, can be accessed by unauthenticated users. This exposure occurs if the email attachment feature is enabled.

4.0
Mar 8, 2025

Post Lockdown WordPress Plugin Information Exposure Vulnerability

A vulnerability allowing information exposure has been identified in the Post Lockdown plugin for WordPress, affecting all versions through 4.0.2. The issue arises from inadequate restrictions on which posts can be included in the 'pl_autocomplete' AJAX action. This flaw enables authenticated attackers with Subscriber-level access and above to access data from password-protected, private, or draft posts that should otherwise be restricted.

2.1
Mar 8, 2025

Shortcode Cleaner Lite Missing Authorization Vulnerability in WordPress

A vulnerability exists in the Shortcode Cleaner Lite plugin for WordPress, affecting all versions through 1.0.9. The issue arises from a lack of proper capability checks in the download_backup() function, allowing authenticated attackers with Subscriber-level access or higher to export arbitrary options. This unauthorized data access could lead to exposure of sensitive information or options that could be manipulated.

2.3
Mar 8, 2025

Code Snippets CPT WordPress Plugin Shortcode Execution Vulnerability

A vulnerability allowing arbitrary shortcode execution has been identified in the Code Snippets CPT plugin for WordPress, affecting all versions through 2.1.0. The issue arises because the plugin permits users to execute actions without proper validation, allowing authenticated attackers with Subscriber-level access or higher to run arbitrary shortcodes.

2.3
Mar 8, 2025

Allow PHP Execute WordPress Plugin PHP Code Injection Vulnerability

A PHP code injection vulnerability exists in the Allow PHP Execute plugin for WordPress, affecting all versions through 1.0. The vulnerability arises because the plugin allows PHP code to be submitted by users with unfiltered HTML privileges. This enables authenticated attackers with Editor-level access or higher to inject PHP code into posts and pages.

2.5
Mar 8, 2025

Post Meta Data Manager WordPress Plugin Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in the Post Meta Data Manager plugin for WordPress, affecting all versions through 1.4.3. The issue arises from the plugin's failure to properly verify the presence of a multisite installation before allowing modifications to user meta. This flaw enables authenticated attackers with Administrator-level access or higher to gain elevated privileges on otherwise inaccessible subsites.

2.1
Mar 8, 2025

Wishlist for WooCommerce Multi Wishlists Per Customer Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress, affecting all versions through 3.1.7. The vulnerability arises from inadequate nonce validation in the 'save_to_multiple_wishlist' function, allowing unauthenticated attackers to manipulate settings and inject malicious scripts by deceiving a site administrator into clicking a link.

2.7
Mar 8, 2025

WordPress Years Since Timeless Texts Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Years Since – Timeless Texts plugin for WordPress, affecting all versions through 1.4.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'years-since' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.4
Mar 8, 2025

HT Mega – Absolute Addons For Elementor DOM-Based Stored Cross-Site Scripting Vulnerability

A DOM-based stored cross-site scripting vulnerability has been identified in the HT Mega – Absolute Addons For Elementor plugin for WordPress, affecting all versions through 2.8.2. The issue arises in the Countdown widget, where inadequate input sanitization and output escaping on user-supplied attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts execute when a user accesses the compromised page. This vulnerability is a result of an incomplete fix for CVE-2024-3307.

2.3
Mar 8, 2025

Tangem SDK Android Offline Wallet Attestation Logic Flaw Vulnerability

A vulnerability exists in the Tangem SDK for Android, specifically in the offline wallet attestation process, prior to version 5.18.3. The issue arises because verification results are ignored during the initial scan of a card, potentially leading to incorrect attestation outcomes. Although this flaw may not have been exploitable in practice, it creates a lapse in the genuineness check process.

2.1
Mar 7, 2025

TOTOLINK EX1800T Stack-Based Buffer Overflow Vulnerability in setRptWizardCfg Function

A critical stack-based buffer overflow vulnerability has been identified in the TOTOLINK EX1800T wireless extender, specifically in version 9.1.0cu.2112_B20220316. The issue arises within the setRptWizardCfg function of the cgi-bin/cstecgi.cgi file, where improper handling of the loginpass argument allows for remote exploitation.

3.1
Mar 7, 2025

TOTOLINK EX1800T OS Command Injection Vulnerability in setRebootScheCfg Function

A critical OS command injection vulnerability has been identified in the TOTOLINK EX1800T router, specifically in version 9.1.0cu.2112_B20220316. The issue arises in the '/cgi-bin/cstecgi.cgi' file, where the 'setRebootScheCfg' function improperly handles the 'mode', 'week', 'minute', and 'recHour' arguments. This vulnerability can be exploited remotely, allowing attackers to inject and execute arbitrary OS commands on the device.

3.1
Mar 7, 2025

TOTOLINK EX1800T OS Command Injection Vulnerability in setDmzCfg Function

A critical OS command injection vulnerability has been identified in the TOTOLINK EX1800T router, specifically in version 9.1.0cu.2112_B20220316. The issue arises in the function setDmzCfg within the file cgi-bin/cstecgi.cgi. The vulnerability can be exploited remotely by manipulating the 'ip' argument, allowing for unauthorized command execution on the operating system.

4.3
Mar 7, 2025

TOTOLINK EX1800T OS Command Injection Vulnerability in setWiFiExtenderConfig Function

A critical OS command injection vulnerability has been identified in the TOTOLINK EX1800T wireless extender, specifically in version 9.1.0cu.2112_B20220316. The issue arises in the setWiFiExtenderConfig function within the cgi-bin/cstecgi.cgi file. The vulnerability allows remote attackers to inject and execute arbitrary operating system commands by manipulating the apcliKey/key argument.

4.3
Mar 7, 2025

PHPGurukul Online Library Management System Unverified Password Change Vulnerability

A vulnerability exists in PHPGurukul Online Library Management System version 3.0, specifically in the password change functionality of the file '/change-password.php'. This vulnerability allows for weak password recovery by manipulating the email or phone number arguments. The issue arises because the system does not verify whether the submitted email and mobile number belong to the user requesting the password change. As a result, attackers can exploit this flaw remotely, bypassing identity checks and changing passwords for any user by using valid email and phone number combinations.

4.4
Mar 7, 2025

Backdrop CMS Bootstrap Lite Theme Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the Bootstrap Lite theme for Backdrop CMS, specifically in versions 1.x prior to 1.x-1.4.5. The issue arises because the theme does not adequately sanitize certain class names, allowing for the potential injection of malicious scripts.

3.7
Mar 7, 2025

Backdrop CMS Bootstrap 5 Lite Theme Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the Bootstrap 5 Lite theme for Backdrop CMS, specifically in versions 1.x prior to 1.x-1.0.3. The issue arises because the theme does not adequately sanitize certain class names, allowing for the potential injection of malicious scripts.

1.6
Mar 7, 2025

Backdrop CMS Link Iframe Formatter Module Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the Link iframe formatter module for Backdrop CMS, specifically in versions 1.x prior to 1.x-1.1.1. The issue arises because the module fails to properly sanitize user input before displaying it, allowing for the potential injection of malicious scripts. This vulnerability can be exploited by users who have the ability to create content with an iFrame field.

3.7
Mar 7, 2025

Backdrop CMS Mail Disguise Module Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the Mail Disguise module for Backdrop CMS, affecting all versions prior to 1.x-1.0.5. The module is designed to obfuscate email addresses to prevent spambots from collecting them. However, it fails to properly validate the data attribute values on links, which could be exploited to inject malicious scripts. This vulnerability requires an attacker to insert link HTML elements with data attributes into the page.

3.7
Mar 7, 2025

Backdrop CMS Masquerade Module Access Bypass Vulnerability

A critical access bypass vulnerability has been identified in the Masquerade module for Backdrop CMS, affecting versions prior to 1.x-1.0.1. This vulnerability allows users to temporarily switch to another user account, potentially masquerading as an administrator. The issue arises because the module's permission to restrict non-administrative users from accessing admin accounts is not consistently enforced. To exploit this vulnerability, an attacker must have a role that includes the 'Masquerade as user' permission.

3.8
Mar 7, 2025

Docmosis Tornado Remote Code Execution Vulnerability via Crafted Script to UNC Path

A remote code execution vulnerability exists in Docmosis Tornado versions through 2.9.7. The issue arises when a remote attacker sends a crafted script to the UNC path input, exploiting the application's handling of path normalization. This vulnerability can be bypassed by URL encoding certain characters, allowing malicious scripts to be executed.

3.0
Mar 7, 2025

Trimble SketchUp Uninitialized Variable Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Trimble SketchUp, specifically within the SKP file parsing process. This issue arises from the improper initialization of memory, allowing attackers to execute arbitrary code in the context of the current process. Exploitation requires user interaction, as the target must open a malicious SKP file.

4.6
Mar 7, 2025

Microsoft Edge Spoofing Vulnerability

A spoofing vulnerability has been identified in Microsoft Edge (Chromium-based) that allows an unauthorized attacker to perform deceptive actions over a network. This issue arises because the user interface incorrectly handles certain actions.

4.7
Mar 7, 2025

Python JSON Logger Remote Code Execution Vulnerability via Missing Dependency

A remote code execution vulnerability has been identified in the Python JSON Logger package, specifically in versions 3.2.0 and 3.2.1. The issue arose from the deletion of the 'msgspec-python313-pre' dependency, which left the name available for reclamation by a third party. If exploited, this vulnerability would allow arbitrary code execution on any user who installed the development dependencies of Python JSON Logger on Python 3.13. The vulnerability has been addressed in version 3.3.0.

3.5
Mar 7, 2025

XWiki Confluence Migrator Pro Sensitive Information Exposure Vulnerability

A vulnerability in XWiki Confluence Migrator Pro versions through 1.11.6 allows guests to download packages containing sensitive information. This issue arises because the application's homepage is publicly accessible.

3.2
Mar 7, 2025

IBM Aspera Shares XML External Entity Injection Vulnerability

A vulnerability allowing XML external entity injection (XXE) has been identified in IBM Aspera Shares versions 1.9.9 through 1.10.0 PL7. This vulnerability arises when the application processes XML data, creating an opportunity for remote authenticated attackers to exploit it. The exploitation of this vulnerability could lead to the exposure of sensitive information or the consumption of memory resources.

2.2
Mar 7, 2025

QNAP QuRouter Command Injection Vulnerability Allowing Arbitrary Command Execution

A command injection vulnerability exists in QNAP QuRouter versions 2.4.x. This vulnerability allows remote attackers with administrator access to execute arbitrary commands on the affected system.

1.7
Mar 7, 2025

QNAP QTS and QuTS hero Out-of-Bounds Write Vulnerability Allowing Memory Corruption

An out-of-bounds write vulnerability has been identified in QNAP's QTS and QuTS hero operating systems, specifically in versions 5.2.x. This vulnerability allows remote attackers with administrator access to modify or corrupt memory. The issue has been resolved in QTS 5.2.3.3006 build 20250108 and later, as well as in QuTS hero h5.2.3.3006 build 20250108 and later.

4.1
Mar 7, 2025

QNAP QTS and QuTS hero Double Free Vulnerability Allowing Memory Modification

A double free vulnerability has been identified in QNAP QTS versions 5.2.x and QuTS hero h5.2.x. This vulnerability allows remote attackers with administrator access to modify memory, potentially leading to further exploitation.

4.1
Mar 7, 2025

QNAP QTS and QuTS hero Out-of-Bounds Write Vulnerability Allowing Memory Corruption

An out-of-bounds write vulnerability has been identified in QNAP's QTS and QuTS hero operating systems, specifically in versions 5.2.x. This vulnerability allows remote attackers with administrator access to modify or corrupt memory. The issue has been addressed in QTS 5.2.3.3006 build 20250108 and later, as well as in QuTS hero h5.2.3.3006 build 20250108 and later.

4.1
Mar 7, 2025

QNAP QuLog Center, Legacy QTS, and QuTS hero Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability exists in QuLog Center, as well as in legacy versions of QTS and QuTS hero. This vulnerability allows remote attackers with administrator access to read application data. The issue has been addressed in QuLog Center versions 1.7.0.829 and 1.8.0.888, as well as in QTS 4.5.4.2957 and QuTS hero h4.5.4.2956, all released in October 2024.

2.5
Mar 7, 2025

QNAP HBS 3 Hybrid Backup Sync Buffer Overflow Vulnerability

A buffer overflow vulnerability has been identified in QNAP HBS 3 Hybrid Backup Sync versions 25.1.x. This vulnerability could be exploited by remote attackers to modify memory or crash processes.

4.6
Mar 7, 2025

QNAP QVPN, Qsync, and Qfinder Pro for Mac TOCTOU Race Condition Vulnerability

A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in QNAP QVPN Device Client for Mac (versions 2.2.x), Qsync Client for Mac (versions 5.1.x), and Qfinder Pro for Mac (versions 7.11.x). This vulnerability allows local attackers with user access to gain unauthorized access to certain resources.

3.1
Mar 7, 2025

QNAP QTS and QuTS hero CRLF Injection Vulnerability Allowing Data Modification

A CRLF injection vulnerability has been identified in multiple QNAP operating system versions, specifically QTS 5.2.x and QuTS hero h5.2.x. This vulnerability allows remote attackers with user access to improperly manipulate application data. The issue arises from inadequate handling of CRLF sequences, which could be exploited to alter how data is processed or displayed.

4.2
Mar 7, 2025

QNAP QTS and QuTS hero Command Injection Vulnerability

A command injection vulnerability exists in multiple QNAP operating system versions, specifically QTS 5.2.x and QuTS hero h5.2.x. This vulnerability allows remote attackers with administrator access to execute arbitrary commands on the affected system.

4.2
Mar 7, 2025

QNAP QTS and QuTS hero CRLF Injection Vulnerability Allowing Data Modification

A CRLF injection vulnerability has been identified in multiple QNAP operating system versions, specifically QTS 5.2.x and QuTS hero h5.2.x. This vulnerability allows remote attackers with administrator access to improperly manipulate application data by exploiting the inadequate handling of CRLF sequences.

4.1
Mar 7, 2025

QNAP Helpdesk Improper Certificate Validation Vulnerability

A vulnerability in QNAP Helpdesk versions 3.3.x has been identified, stemming from improper certificate validation. This issue could enable remote attackers to compromise the security of the system. However, systems with Helpdesk disabled are not affected.

1.5