CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Feb 19, 2025

ChurchCRM Boolean-Based and Time-Based Blind SQL Injection Vulnerability in BatchWinnerEntry Functionality

A SQL injection vulnerability has been identified in ChurchCRM versions through 5.13.0. This vulnerability allows attackers to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL injection in the BatchWinnerEntry functionality. The issue arises because the CurrentFundraiser parameter is concatenated into an SQL query without proper sanitization, enabling attackers to manipulate database queries and execute arbitrary commands. Exploitation of this vulnerability could lead to unauthorized data access, modification, or deletion. Notably, this vulnerability requires administrator privileges to exploit.

3.7
Feb 19, 2025

ChurchCRM Boolean-Based and Time-Based Blind SQL Injection Vulnerability in DonatedItemEditor

A SQL injection vulnerability has been identified in ChurchCRM versions through 5.13.0. This vulnerability allows attackers to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL injection in the DonatedItemEditor functionality. The CurrentFundraiser parameter is concatenated into an SQL query without proper sanitization, enabling attackers to manipulate database queries and execute arbitrary commands. This could lead to unauthorized data exfiltration, modification, or deletion. Exploitation of this vulnerability requires administrator privileges.

3.7
Feb 19, 2025

ChurchCRM Boolean-Based Blind SQL Injection Vulnerability in EditEventAttendees Function

A boolean-based blind SQL injection vulnerability has been identified in ChurchCRM versions through 5.13.0. This vulnerability allows attackers with administrator privileges to execute arbitrary SQL queries by manipulating the EID parameter, which is directly concatenated into an SQL query without proper sanitization. Exploitation of this vulnerability could lead to unauthorized data access, modification, or deletion.

3.7
Feb 19, 2025

ChurchCRM Time-Based Blind SQL Injection Vulnerability in EditEventAttendees.php

A time-based blind SQL injection vulnerability has been identified in ChurchCRM versions through 5.13.0. The issue resides in the EditEventAttendees.php file, specifically within the EN_tyid parameter, which is vulnerable to injection as it is directly included in an SQL query without adequate sanitization. This vulnerability requires administrator permissions to exploit. Attackers can use this flaw to introduce malicious SQL commands, potentially leading to unauthorized data access or manipulation by exploiting the time-based nature of the injection to extract information from the database.

3.7
Feb 19, 2025

ChurchCRM Reflected Cross-Site Scripting Vulnerability in EditEventAttendees.php Allowing Session Hijacking

A reflected cross-site scripting vulnerability has been identified in ChurchCRM version 5.13.0, specifically on the EditEventAttendees.php page. This issue allows an attacker with administrative privileges to execute arbitrary JavaScript in the context of a victim's browser, targeting the EID parameter. The exploitation of this vulnerability could lead to session hijacking, as attackers can steal session cookies, impersonate users, and gain unauthorized access to the application.

3.6
Feb 19, 2025

OpenVSX Improper Authorization Vulnerability in Namespace Details API

A vulnerability exists in OpenVSX versions 0.9.0 through 0.20.0, allowing users to edit namespace details via the '/user/namespace/{namespace}/details' API, regardless of their ownership or contribution status. Affected details include the namespace name, description, website, support link, and social media links. The vulnerability also extends to the '/user/namespace/{namespace}/details/logo' endpoint, where users could change the namespace logo without proper authorization.

3.8
Feb 19, 2025

Raptive Ads WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Data Reset

A vulnerability exists in the Raptive Ads plugin for WordPress, all versions through 3.6.3, due to a lack of proper capability checks in the site_ads_files_reset() and cls_file_reset() functions. This flaw enables unauthenticated attackers to reset ad and CLS files, potentially disrupting ad management and performance optimization settings.

2.5
Feb 19, 2025

Raptive Ads WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Raptive Ads plugin for WordPress, affecting all versions through 3.6.3. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link or performing a similar action.

2.7
Feb 19, 2025

DeBounce Email Validator WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the DeBounce Email Validator plugin for WordPress, affecting all versions through 5.7. The vulnerability arises from inadequate nonce validation on the 'debounce_email_validator' page, allowing unauthenticated attackers to manipulate settings and inject malicious scripts. Exploitation requires tricking a site administrator into clicking a link.

2.5
Feb 19, 2025

Disable Auto Updates WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Disable Auto Updates plugin for WordPress, affecting all versions through 1.4. The issue arises from inadequate nonce validation on the 'disable-auto-updates' page, allowing unauthenticated attackers to disable auto updates by sending a forged request, provided they can persuade a site administrator to click a link.

2.0
Feb 19, 2025

WordPress Portfolio Builder - Portfolio Gallery Missing Authorization Vulnerability in Video Addition Function

A vulnerability exists in the WordPress Portfolio Builder - Portfolio Gallery plugin, specifically in versions through 1.1.7. The issue arises from a lack of proper capability checks in the 'add_video' function, allowing unauthenticated users to add arbitrary videos to any portfolio gallery. This unauthorized data modification could be exploited by attackers to manipulate portfolio content without authentication.

3.5
Feb 19, 2025

WP Media Category Management Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Media Category Management plugin for WordPress, affecting versions 2.0 to 2.3.3. The vulnerability arises from inadequate nonce validation in the 'wp_mcm_handle_action_settings()' function, allowing unauthenticated attackers to manipulate plugin settings. This could include changing the media taxonomy, the base slug for media categories, and the default media category, by tricking a site administrator into clicking a link that triggers the forged request.

3.0
Feb 19, 2025

Education Addon for Elementor Insecure Direct Object Reference Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Education Addon for Elementor plugin for WordPress, affecting all versions through 1.3.1. The vulnerability arises from missing validation on a user-controlled key in the naedu_elementor_template shortcode. This flaw enables authenticated attackers with Contributor-level access and above to access and extract information from non-public posts, including drafts, password-protected content, and restricted posts. The issue specifically pertains to posts created with Elementor.

2.1
Feb 19, 2025

Pure Chat WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Pure Chat – Live Chat & More! WordPress plugin, affecting all versions through 2.4. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts would execute when a user accesses the compromised page.

2.4
Feb 19, 2025

PeproDev Ultimate Invoice WordPress Plugin Insecure Direct Object Reference Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the PeproDev Ultimate Invoice plugin for WordPress, affecting all versions through 2.0.8. The vulnerability arises in the invoicing viewer, where missing validation on a user-controlled key allows unauthenticated attackers to access invoices for completed orders. These invoices may contain personally identifiable information (PII) of users.

2.0
Feb 19, 2025

Pollin WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Pollin plugin for WordPress, affecting all versions through 1.01.1. The issue arises from inadequate escaping of user-supplied data in the 'question' parameter, coupled with insufficient preparation of the SQL query. This vulnerability allows unauthenticated attackers to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive information from the database.

2.5
Feb 19, 2025

Pollin WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Pollin plugin for WordPress, affecting all versions through 1.01.1. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.

2.5
Feb 19, 2025

Widget BUY.BOX Stored Cross-Site Scripting Vulnerability for WordPress

A stored cross-site scripting vulnerability has been identified in the Widget BUY.BOX plugin for WordPress, affecting all versions through 3.1.5. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'buybox-widget' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected page.

2.3
Feb 19, 2025

Categorized Gallery Plugin SQL Injection Vulnerability for WordPress

A SQL injection vulnerability has been identified in the Categorized Gallery Plugin for WordPress, affecting all versions up to and including 2.0. The issue arises from inadequate escaping of user-supplied parameters in the 'field' attribute of the 'image_gallery' shortcode, coupled with a lack of proper preparation in the SQL query. This vulnerability allows authenticated attackers with Contributor-level access and above to inject additional SQL queries into existing ones, potentially leading to the extraction of sensitive information from the database.

2.7
Feb 19, 2025

Cosmic Blocks WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress, affecting all versions through 1.3.0. The vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'cwp_social_share' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the compromised pages.

1.6
Feb 19, 2025

Coaching Staffs WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Coaching Staffs plugin for WordPress, affecting all versions through 1.4. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'mstw-cs-table' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.7
Feb 19, 2025

Responsive Flickr Slideshow WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Responsive Flickr Slideshow plugin for WordPress, affecting all versions through 2.6.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'fshow' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected page.

2.3
Feb 19, 2025

Store Locator Widget for WordPress Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Store Locator Widget plugin for WordPress, affecting all versions prior to 20200131. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'storelocatorwidget' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected page.

2.3
Feb 19, 2025

Team Builder For WPBakery Page Builder Local File Inclusion Vulnerability

A local file inclusion vulnerability has been identified in the Team Builder For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress, affecting all versions through 1.0. The vulnerability arises in the 'team-builder-vc' shortcode, allowing authenticated attackers with Contributor-level access and above to include and execute arbitrary files on the server. This exploitation can be used to bypass access controls, access sensitive data, or execute code by including files that contain PHP code, especially in scenarios where 'safe' file types like images can be uploaded and included.

1.9
Feb 19, 2025

Team Builder For WPBakery Page Builder Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Team Builder For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress. This issue affects all versions through 1.0 and arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'team-builder-vc' shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will execute when a user views the affected page.

2.3
Feb 19, 2025

YouTube Playlists with Schema Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the YouTube Playlists with Schema plugin for WordPress, affecting all versions through 2.6.1. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'yt_grid' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.7
Feb 19, 2025

Trash Duplicate and 301 Redirect WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Post Deletion

A vulnerability exists in the Trash Duplicate and 301 Redirect plugin for WordPress, in all versions through 1.9. The issue arises from a missing capability check on the 'duplicates-action-top' action, allowing unauthenticated attackers to delete arbitrary posts or pages. This unauthorized data deletion could lead to significant content loss for users.

2.5
Feb 19, 2025

WP Wiki Tooltip Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Wiki Tooltip plugin for WordPress, affecting all versions through 2.0.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'wiki' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Feb 19, 2025

Apptivo Business Site CRM Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Apptivo Business Site CRM plugin for WordPress, affecting all versions through 5.3. The issue arises from inadequate nonce validation on the 'awp_ip_deny' page, allowing unauthenticated attackers to block IP addresses by sending a forged request, provided they can persuade a site administrator to click a link.

2.9
Feb 19, 2025

ADFO WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the ADFO – Custom Data in Admin Dashboard plugin for WordPress, affecting all versions through 1.9.1. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'adfo_list' shortcode. This flaw allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages, which are executed when users access the compromised pages.

1.6
Feb 19, 2025

Yay! Forms WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Yay! Forms WordPress plugin, specifically in versions through 1.2.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'yayforms' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.3
Feb 19, 2025

Digihood HTML Sitemap Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Digihood HTML Sitemap plugin for WordPress, affecting all versions through 3.1.1. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.

3.0
Feb 19, 2025

Lexicata WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Lexicata plugin for WordPress, affecting all versions through 1.0.16. The issue arises from the use of add_query_arg without proper escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could execute if a user is tricked into clicking a specially crafted link.

2.0
Feb 19, 2025

CanadaHelps Embedded Donation Form WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the CanadaHelps Embedded Donation Form plugin for WordPress, affecting all versions through 1.0.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'embedcdn' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected page.

2.3
Feb 19, 2025

UMich OIDC Login WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the UMich OIDC Login plugin for WordPress, affecting all versions up to and including 1.2.0. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'umich_oidc_button' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.7
Feb 19, 2025

UltraEmbed Advanced Iframe WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the UltraEmbed – Advanced Iframe Plugin for WordPress, specifically in versions through 1.0.3. This vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'iframe' shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will execute when a user views the affected page.

1.6
Feb 19, 2025

iniparser Heap-Based Buffer Overflow Vulnerability in iniparser_dumpsection_ini()

A heap-based buffer overflow vulnerability has been identified in the iniparser library, specifically in the function iniparser_dumpsection_ini(). This vulnerability allows attackers to read out-of-bounds memory. The issue arises from the use of sprintf() to copy a string that exceeds the destination buffer's size, leading to a buffer overflow. The vulnerability was discovered through fuzz testing.

4.5
Feb 19, 2025

Movable Type Reflected Cross-Site Scripting Vulnerability in User Information Edit Page

A reflected cross-site scripting vulnerability has been identified in Movable Type, affecting versions through 8.4.1 in the 8.4.x series, versions through 8.0.5 in the 8.0.x series, and several versions in the 2.x series. This vulnerability occurs on the user information edit page when the Multi-Factor Authentication plugin is enabled. A logged-in user who accesses a crafted page may have arbitrary scripts executed in their web browser.

4.2
Feb 19, 2025

Movable Type Stored Cross-Site Scripting Vulnerability in MT Block Editor HTML Edit Mode

A stored cross-site scripting vulnerability has been identified in Movable Type, specifically in versions through 8.4.1 of the 8.4.x and 8.0.x series, as well as in Movable Type Premium 2.06 and earlier. This vulnerability occurs in the HTML edit mode of the MT Block Editor when TinyMCE6 is used as a rich text editor. It allows for the execution of arbitrary scripts in the web browser of a logged-in user.

3.7
Feb 19, 2025

Movable Type Stored Cross-Site Scripting Vulnerability in MT Block Editor

A stored cross-site scripting vulnerability has been identified in Movable Type and Movable Type Advanced, affecting versions through 8.4.1 and 8.0.5, as well as various 2.x and cloud editions. The vulnerability resides in the custom block edit page of the MT Block Editor, where an attacker can execute arbitrary scripts in the web browser of a logged-in user.

3.7
Feb 19, 2025

Visualizer: Tables and Charts Manager for WordPress Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Visualizer: Tables and Charts Manager for WordPress plugin, affecting all versions through 3.11.8. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's Import Data From File feature. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when a user accesses the injected page.

5.2
Feb 19, 2025

User Private Files WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress, affecting all versions through 2.1.3. The vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts. These scripts are executed when a user accesses the compromised page.

3.1
Feb 19, 2025

Master Slider WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Master Slider WordPress plugin, affecting versions prior to 3.10.5. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as Editors and above, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.

2.8
Feb 19, 2025

Royal Elementor Addons and Templates WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Royal Elementor Addons and Templates plugin for WordPress, affecting all versions through 1.7.1007. The vulnerability arises from inadequate nonce validation in the 'wpr_filter_woo_products' function, allowing unauthenticated attackers to inject malicious scripts by tricking a site administrator into clicking a link.

4.4
Feb 19, 2025

Age Verification for Checkout - WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Age Verification for Your Checkout Page WordPress plugin, specifically in version 1.20.0. The issue arises because the plugin dynamically generates web content without properly validating the source of potentially untrusted data, particularly in the 'myapp/class-wc-integration-agechecker-integration.php' file.

2.4
Feb 19, 2025

Easypromos Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Easypromos Plugin for WordPress, affecting all versions through 1.3.8. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's Easypromos shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Feb 19, 2025

Subscribe2 WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress, affecting all versions through 10.43. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts are executed when users access the compromised pages.

4.8
Feb 19, 2025

Synway SMG Gateway Management Software Command Injection Vulnerability in 9-12ping.php

A command injection vulnerability has been identified in the Synway SMG Gateway Management Software, specifically in versions prior to 20250204. The issue resides in the 9-12ping.php file, where the 'retry' parameter can be manipulated to execute arbitrary commands on the server. This vulnerability can be exploited remotely without authentication, potentially leading to unauthorized command execution, disclosure of sensitive information, and disruption of service.

4.0
Feb 19, 2025

Barebox Integer Overflow Vulnerability in ext4 Filesystem Handling

A vulnerability exists in barebox versions prior to 2025.01.0 within the ext4 filesystem handling, specifically in the 'ext4fs_read_symlink' function. The issue arises from an integer overflow when the function processes a crafted ext4 filesystem that includes an inode size of 0xffffffff. This overflow occurs because the function adds one to a little-endian 32-bit variable, leading to a zero allocation when the 'zalloc' function is called. Consequently, the function later uses the invalid inode size to copy data, allowing for a memory overwrite. This vulnerability is related to CVE-2024-57256.

1.7
Feb 19, 2025

Barebox Integer Overflow Vulnerability in Request2size Function Allows Memory Corruption

An integer overflow vulnerability has been identified in the Barebox bootloader, specifically in versions prior to 2025.01.0. The issue arises in the 'request2size' function within 'common/dlmalloc.c', where a size_t variable is improperly cast to a long. This casting can lead to an overflow, allowing values close to LONG_MAX to be misinterpreted, causing the function to return an incorrect minimum size. This vulnerability is related to another identified issue, CVE-2024-57258.

2.2