Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Get Started
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash
  • Business and Enterprise Solutions
  • CMS

CMS

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Selected category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    22 Apr 2025 Business and Enterprise Solutions
    WordPress: Stored XSS via Preview Data Function in WP Import Export Lite Plugin

    In WP Import Export Lite plugin for WordPress versions up to and including 3.9.27 a medium severity vulnerability CVE-2025-2839 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the wpiePreviewData function, due to insufficient input sanitization and output escaping. To address this issue, users should upgrade WP Import Export Lite plugin to versions 3.9.28 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2839.

    Read more
    CMS
    21 Apr 2025 Business and Enterprise Solutions
    WordPress: Authenticated Users Can Delete Arbitrary Files Leading to RCE in Download Manager Plugin

    In Download Manager plugin for WordPress versions up to and including 3.3.12 a high severity vulnerability (CVE-2025-3404) was detected. This vulnerability allows authenticated attackers with Author-level access or higher to delete arbitrary files on the server via insufficient file path validation in the savePackage function, potentially leading to remote code execution if critical files like wp-config.php are removed. To address this issue, users should update Download Manager plugin to versions 3.3.13 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3404.

    Read more
    CMS
    21 Apr 2025 Business and Enterprise Solutions
    WordPress: Stored XSS via Auto-Refresh Log in Debug Log Manager Plugin

    In Debug Log Manager plugin for WordPress versions up to and including 2.3.4 a high severity vulnerability CVE-2025-3809 was detected. This vulnerability allows unauthenticated attackers to inject malicious JavaScript via the auto-refresh debug log due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Debug Log Manager plugin to versions 2.3.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3809.

    Read more
    CMS
    17 Apr 2025 Business and Enterprise Solutions
    Liferay: Stored XSS in Radio Button Custom Fields Allows JavaScript Injection by Authenticated Users

    In Liferay Portal versions 7.2.0 through 7.4.3.129 and Liferay DXP versions 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, 7.3 GA through update 36 and 7.2 GA through fix pack 20 a medium severity vulnerability CVE-2025-3760 was detected. This vulnerability allows remote authenticated attackers to inject malicious JavaScript into a page using radio button type custom fields. To address this issue, users should upgrade Liferay Portal to versions 7.4.3.132 and Liferay DXP to versions 2024.Q1.13, 2024.Q3.10 or 2025.Q1.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3760.

    Read more
    CMS
    10 Apr 2025 Business and Enterprise Solutions
    WordPress: Privilege Escalation Vulnerability in Embedder Plugin

    In Embedder plugin for WordPress versions 1.3 to 1.3.5 a high severity vulnerability CVE-2025-3417 was detected. This vulnerability allows authenticated attackers with Subscriber-level access and above to modify data due to a missing capability check in the ajax_set_global_option() function, enabling them to change the default registration role to administrator and gain administrative access to the site. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3417.

    Read more
    CMS
    10 Apr 2025 Business and Enterprise Solutions
    WordPress: Arbitrary Shortcode Execution Vulnerability in ORDER POST Plugin

    In ORDER POST plugin for WordPress versions 2.0.2 and prior a high severity vulnerability CVE-2025-2805 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes due to improper validation of values before running do_shortcode. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2805.

    Read more
    CMS
    10 Apr 2025 Business and Enterprise Solutions
    WordPress: Reflected Cross-Site Scripting Vulnerability in Feedify Plugin

    In Feedify plugin for WordPress versions prior to 2.4.6 a high severity vulnerability CVE-2024-13874 was detected. This vulnerability allows attackers to exploit a lack of sanitization and escaping of parameters, leading to Reflected Cross-Site Scripting (XSS) attacks that could target high-privilege users such as administrators. To address this issue, users should upgrade Feedify plugin to versions 2.4.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13874.

    Read more
    CMS
    8 Apr 2025 Business and Enterprise Solutions
    Umbraco: Authenticated Path Traversal File Upload Vulnerability

    In Umbraco versions 14.3.3 and prior, 15.3.0 and prior a medium severity vulnerability CVE-2025-32017 was detected. This vulnerability allows authenticated users of the Umbraco backoffice to exploit a path traversal flaw in the management API, enabling them to upload files to incorrect locations. To address this issue, users should upgrade Umbraco to versions 14.3.4 or 15.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-32017.

    Read more
    CMS
    3 Apr 2025 Business and Enterprise Solutions
    Drupal: Bypass of Two-Factor Authentication (TFA) Security

    In Drupal versions prior to 1.10.0 a low severity vulnerability CVE-2025-31694 was detected. This vulnerability allows attackers to bypass security measures within the Two-factor Authentication (TFA) module through forceful browsing, potentially granting unauthorized access to sensitive user data and administrative functionalities. To address this issue, users should upgrade Drupal TFA module to versions 1.10.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-31694.

    Read more
    CMS
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base
    © HOSSTED 2025 All rights reserved
    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy