In GitLab CE/EE versions from 16.7 before 17.9.7, 17.10 before 17.10.5 and 17.11 before 17.11.1 a medium severity vulnerability CVE-2025-0639 was discovered. This issue affects service availability through the issue preview feature. To address this issue, users should upgrade GitLab CE/EE to versions 17.9.7, 17.10.5 or 17.11.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0639.
Read more Developer ToolsIn GitLab EE versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5 and 17.11 prior to 17.11.1 a medium severity vulnerability CVE-2024-12244 was discovered. This issue in access controls may allow users to view restricted project information even when related features are disabled. To address this issue, users should upgrade GitLab EE to versions 17.9.7, 17.10.5 or 17.11.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12244.
Read more Developer ToolsIn Grafana XY Chart plugin versions 11.6.0 prior to 11.6.0+security-01, 11.5.0 prior to 11.5.3+security-01, 11.4.0 prior to 11.4.3+security-01, 11.3.0 prior to 11.3.5+security-01 and 11.2.0 prior to 11.2.8+security-01 a medium severity vulnerability CVE-2025-2703 was detected. This DOM-based XSS issue allows a user with Editor permissions to modify a panel and execute arbitrary JavaScript. To address this issue, users should upgrade Grafana XY Chart plugin to versions 1.6.0+security-01, 11.5.3+security-01, 11.4.3+security-01, 11.3.5+security-01 and 11.2.8+security-01. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2703.
Read more Data AnalyticsIn Mattermost versions 10.4.x ≤ 10.4.2, 10.5.x ≤ 10.5.0 and 9.11.x ≤ 9.11.10 a low severity vulnerability CVE-2025-41423 was detected. This issue allows any user or attacker to delete posts created by the Playbooks bot through the `/plugins/playbooks/api/v0/signal/keywords/ignore-thread` API endpoint, even without channel access or proper permissions. To address this issue, users should upgrade Mattermost to versions 10.6.0, 10.4.3, 10.5.1, 9.11.11 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-41423.
Read more CommunicationIn Klarna Checkout for WooCommerce plugin for WordPress versions prior to 2.13.5 a medium severity vulnerability CVE-2024-13925 was detected. This vulnerability allows unauthenticated attackers to flood log files using an exposed WooCommerce Ajax endpoint, rapidly consuming disk space and potentially filling the entire disk. To address this issue, users should upgrade Klarna Checkout for WooCommerce plugin to versions 2.13.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13925.
Read more CMSIn Fluent Forms plugin for WordPress versions up to and including 6.0.2 a medium severity vulnerability CVE-2025-3615 was detected. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject malicious scripts via the form-submission.js script due to insufficient input sanitization and output escaping. These scripts execute when a user accesses an injected page. To address this issue, users should upgrade Fluent Forms plugin to versions 6.0.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3615.
Read more CMSIn WP Editor plugin for WordPress versions up to and including 1.2.9.13 a high severity vulnerability CVE-2025-3294 was detected. This vulnerability allows authenticated attackers with Administrator-level access or higher to overwrite arbitrary files on the server due to missing file path validation. To address this issue, users should upgrade WP Editor plugin to versions 1.2.9.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3294.
Read more CMSIn Ultimate Dashboard plugin for WordPress versions before 3.8.6 a low severity vulnerability CVE-2025-1523 was detected. This vulnerability allows high-privileged users, such as admins, to perform Stored Cross-Site Scripting (XSS) attacks due to improper sanitization and escaping of certain settings – even when the unfiltered_html capability is disallowed, such as in multisite environments. To address this issue, users should upgrade Ultimate Dashboard plugin to versions 3.8.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1523.
Read more CMSIn WP Editor plugin for WordPress versions up to and including 1.2.9.1 a medium severity vulnerability CVE-2025-3295 was detected. This vulnerability allows authenticated attackers with Administrator-level access or higher to read arbitrary files on the affected site’s server, potentially exposing sensitive information. To address this issue, users should upgrade WP Editor plugin to versions 1.2.9.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3295.
Read more CMS