2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-12399
Alex Reservations: Smart Restaurant Booking Web Windows
7.2
HIGH
EPSS
0.2%
2025 CWE-434 2 PoCs

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-30349
IMP Web
7.2
HIGH
EPSS
40.3%
2025 CWE-79 2 PoCs

Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.

CVE-2025-15380
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Windows
7.2
HIGH
EPSS
0.2%
2025 CWE-79 1 PoC

The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This is due to insufficient input sanitization and output escaping when processing preview data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute when a user visits a malicious page that auto-submits a form to the vulnerable site.

CVE-2025-22210
Hikashop component for Joomla Web Database
7.2
HIGH
EPSS
0.1%
2025 CWE-89 1 PoC

A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.

CVE-2025-46657
Karazal Web
7.2
HIGH
EPSS
0.1%
2025 CWE-79 2 PoCs

Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.

CVE-2025-63227
Software Genérico Web
7.2
HIGH
EPSS
0.1%
2025 1 PoC

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This allows the attacker to execute arbitrary commands on the server, potentially leading to full system compromise.

CVE-2025-63417
Software Genérico Web
7.2
HIGH
EPSS
0.1%
2025 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated attackers to inject arbitrary web scripts or HTML via the chat message input field. This malicious content is stored and then executed in the context of other users' browsers when they view the malicious message, potentially leading to session hijacking, account takeover, or other client-side attacks.

CVE-2025-6085
Make Connector Web Windows
7.2
HIGH
EPSS
1.0%
2025 CWE-434 1 PoC

The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' function in all versions up to, and including, 1.5.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-0924
WP Activity Log Web Windows
7.2
HIGH
EPSS
8.5%
2025 CWE-79 1 PoC

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-12973
S2B AI Assistant – ChatBot, AI Agents, ChatGPT API, Image Generator Web Windows
7.2
HIGH
EPSS
0.1%
2025 CWE-434 2 PoCs

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function in all versions up to, and including, 1.7.8. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-60500
Software Genérico Web
7.2
HIGH
EPSS
0.2%
2025 1 PoC

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.

CVE-2025-54478
Mattermost Confluence Plugin Web
7.2
HIGH
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.

CVE-2025-10686
Creta Testimonial Showcase Web Windows
7.2
HIGH
EPSS
0.1%
2025 1 PoC

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

CVE-2025-13071
Custom Admin Menu Web Windows
7.1
HIGH
EPSS
0.0%
2025 1 PoC

The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-2960
TEW-637AP Web
7.1
HIGH
EPSS
0.2%
2025 CWE-476 1 PoC

A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affects the function sub_41DED0 of the file /bin/goahead of the component HTTP Request Handler. The manipulation leads to null pointer dereference. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-39664
Checkmk Web
7.1
HIGH
EPSS
0.1%
2025 CWE-22 1 PoC

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.

CVE-2025-8281
WP Talroo Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin and unauthenticated users.

CVE-2025-1486
WoWPth Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-15396
Library Viewer Web Windows
7.1
HIGH
EPSS
0.0%
2025 1 PoC

The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-13073
HandL UTM Grabber / Tracker Web Windows
7.1
HIGH
EPSS
0.0%
2025 1 PoC

The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin