38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-2005
Front End Users Web Windows
9.8
CRITICAL
EPSS
1.5%
2025 CWE-434 3 PoCs

The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-26198
Software Genérico Web Database Cloud
9.8
CRITICAL
EPSS
1.0%
2025 2 PoCs

CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and bypass authentication, gaining unauthorized administrative access. The vulnerability is triggered when an attacker supplies specially crafted input in the username field, such as ' OR '1'='1, leading to complete compromise of the login mechanism and potential exposure of sensitive bac

CVE-2025-66438
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get_html_and_style() triggers the rendering of the html field inside a Print Format document using frappe.render_template(template, doc) via the get_rendered_template() call chain. Although ERPNext wraps Jinja2 in a SandboxedEnvironment, it exposes sensitive functions such as frappe.db.sql through get_safe_globals(). An authenticated attacker with permission to create or modify a Print Format can inject arbitrary Jinja e

CVE-2025-50707
Software Genérico Web
9.8
CRITICAL
EPSS
1.7%
2025 1 PoC

An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component

CVE-2025-9967
Orion SMS OTP Verification. Web Windows
9.8
CRITICAL
EPSS
0.2%
2025 CWE-288 1 PoC

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's password to a one-time password if the attacker knows the user's phone number

CVE-2025-70149
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

CVE-2025-63228
Software Genérico Web
9.8
CRITICAL
EPSS
0.9%
2025 1 PoC

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this by sending a crafted POST request with a malicious file (e.g., a PHP webshell) to the server. The uploaded file is stored in the /upload/ directory, enabling remote code execution and full system compromise.

CVE-2025-61246
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

CVE-2025-4334
Simple User Registration Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
34.1%
2025 CWE-269 3 PoCs

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.

CVE-2025-1307
Newscrunch Web Windows
9.8
CRITICAL
EPSS
20.4%
2025 CWE-862 1 PoC

The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-14892
Prime Listing Manager Web Windows
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.

CVE-2025-1661
HUSKY – Products Filter Professional for WooCommerce Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2025 CWE-22 3 PoCs

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2025-9083
Ninja Forms Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2025-31033
Buddypress Humanity Web
9.8
CRITICAL
EPSS
0.2%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2.

CVE-2025-5394
Alone – Charity Multipurpose Non-profit WordPress Theme Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
17.5%
2025 CWE-862 4 PoCs

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. CVE-2025-54019 is likely a duplicate of this.

CVE-2025-9286
Appy Pie Connect for WooCommerce Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 CWE-620 1 PoC

The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to reset the password of arbitrary users, including administrators, thereby gaining administrative access.

CVE-2025-8047
disable-right-click-powered-by-pixterme Web Cloud Windows
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security services. Users that pay are added to allowedDomains to suppress the popup.

CVE-2025-29462
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.

CVE-2025-4578
File Provider Web Database Windows
9.8
CRITICAL
EPSS
0.7%
2025 2 PoCs

The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2025-12463
G-Cam Web Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.