13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-5961
WPvivid — Backup, Migration & Staging Web Windows ⚡ nuclei
7.2
HIGH
EPSS
2.0%
2025 CWE-434 3 PoCs

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload

CVE-2025-4428
🔥 KEV Endpoint Manager Mobile Web
7.2
HIGH
EPSS
26.2%
2025 CWE-94 3 PoCs

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

CVE-2025-63227
Software Genérico Web
7.2
HIGH
EPSS
0.1%
2025 1 PoC

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This allows the attacker to execute arbitrary commands on the server, potentially leading to full system compromise.

CVE-2025-63417
Software Genérico Web
7.2
HIGH
EPSS
0.1%
2025 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated attackers to inject arbitrary web scripts or HTML via the chat message input field. This malicious content is stored and then executed in the context of other users' browsers when they view the malicious message, potentially leading to session hijacking, account takeover, or other client-side attacks.

CVE-2025-54478
Mattermost Confluence Plugin Web
7.2
HIGH
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.

CVE-2025-45753
Software Genérico Web
7.2
HIGH
EPSS
0.4%
2025 1 PoC

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

CVE-2025-44004
Mattermost Confluence Plugin Web
7.2
HIGH
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.

CVE-2025-12399
Alex Reservations: Smart Restaurant Booking Web Windows
7.2
HIGH
EPSS
0.2%
2025 CWE-434 2 PoCs

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-6085
Make Connector Web Windows
7.2
HIGH
EPSS
1.0%
2025 CWE-434 1 PoC

The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' function in all versions up to, and including, 1.5.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-10686
Creta Testimonial Showcase Web Windows
7.2
HIGH
EPSS
0.1%
2025 1 PoC

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

CVE-2025-7050
Use-your-Drive | Google Drive plugin for WordPress Web Windows
7.2
HIGH
EPSS
0.2%
2025 CWE-79 1 PoC

The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability can be exploited by the lowest authentication level permitted to upload files, including unauthenticated users, once a file upload shortcode is published on a publicly accessi

CVE-2025-46657
Karazal Web
7.2
HIGH
EPSS
0.1%
2025 CWE-79 2 PoCs

Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.

CVE-2025-6586
Download Plugin Web Windows
7.2
HIGH
EPSS
0.6%
2025 CWE-434 2 PoCs

The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall function in all versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-12973
S2B AI Assistant – ChatBot, AI Agents, ChatGPT API, Image Generator Web Windows
7.2
HIGH
EPSS
0.1%
2025 CWE-434 2 PoCs

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function in all versions up to, and including, 1.7.8. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-0924
WP Activity Log Web Windows
7.2
HIGH
EPSS
8.5%
2025 CWE-79 1 PoC

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-4190
CSV Mass Importer Web Windows
7.2
HIGH
EPSS
0.2%
2025 3 PoCs

The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2025-64050
Software Genérico Web
7.2
HIGH
EPSS
0.6%
2025 1 PoC

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.

CVE-2025-60500
Software Genérico Web
7.2
HIGH
EPSS
0.2%
2025 1 PoC

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.

CVE-2025-22210
Hikashop component for Joomla Web Database
7.2
HIGH
EPSS
0.1%
2025 CWE-89 1 PoC

A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.

CVE-2025-15380
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Windows
7.2
HIGH
EPSS
0.2%
2025 CWE-79 1 PoC

The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This is due to insufficient input sanitization and output escaping when processing preview data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute when a user visits a malicious page that auto-submits a form to the vulnerable site.