In the Ninja Forms WordPress plugin versions prior to 3.10.1 a low severity vulnerability CVE-2025-2524 was detected. This vulnerability allows high privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (e.g., in a multisite setup), due to insufficient sanitization and escaping of plugin settings. To address this issue, users should upgrade the Ninja Forms WordPress plugin to version 3.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2524.
Read more CMSIn Pgpool-II versions 4.0 and 4.1 series, 4.2.0 to 4.2.21, 4.3.0 to 4.3.14, 4.4.0 to 4.4.11, 4.5.0 to 4.5.6 and 4.6.0 a critical severity vulnerability CVE-2025-46801 was detected. This vulnerability allows attackers to bypass authentication and log in as arbitrary users, enabling them to read, modify, or disable data in the connected database. To address this issue, users should upgrade Pgpool-II to versions 4.6.1, 4.5.7, 4.4.12, 4.3.15, 4.2.22 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-46801.
Read more DatabaseIn Wise Chat plugin for WordPress versions up to and including 3.3.3 a high severity vulnerability CVE-2024-13613 was detected. This vulnerability allows unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory, potentially exposing file attachments from chat messages. To address this issue, users should upgrade Wise Chat plugin to versions 3.3.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13613.
Read more CMSIn WP Booking Calendar plugin for WordPress versions up to and including 10.11.1 a medium severity vulnerability CVE-2025-4669 was detected. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts via the wpbc shortcode, which execute when a user accesses an injected page, due to insufficient input sanitization and output escaping. To address this issue, users should upgrade WP Booking Calendar plugin to versions 10.11.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4669.
Read more CMSIn Jupiter X Core plugin for WordPress versions up to and including 4.8.12 a medium severity vulnerability CVE-2025-3888 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via SVG file inclusion due to insufficient input sanitization and output escaping, leading to script execution when a user accesses the affected page. To address this issue, users should upgrade Jupiter X Core plugin to versions 4.9.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3888.
Read more CMSIn EventON Pro plugin versions up to and including 4.9.6 a medium severity vulnerability CVE-2025-3527 was detected. This vulnerability allows authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts due to a missing capability check in the assets/lib/settings/settings.js file, leading to script execution when a user accesses an affected page. To address this issue, users should upgrade EventON Pro plugin to versions 4.9.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3527.
Read more CMSIn Zulip versions 10.0 to before 10.3 a medium severity vulnerability CVE-2025-47930 was detected. This vulnerability allows attackers to bypass the “Who can create public channels” access control by creating a private or web-public channel and then changing its privacy setting to public. Similarly, private channels can be created without proper permissions using the API or by altering HTML. To address this issue, users should upgrade Zulip to version 10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-47930.
Read more CommunicationIn Next.js versions prior to 14.2.24 and 15.1.6 a low severity vulnerability CVE-2025-32421 was detected. This race-condition vulnerability in the Pages Router under certain misconfigurations causes normal endpoints to serve `pageProps` data instead of standard HTML. To address this issue, users should upgrade Next.js to versions 15.1.6 or 14.2.24. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-32421.
Read more Application DevelopmentIn iTop versions prior to 3.1.3 and 3.2.1 a medium severity vulnerability CVE-2024-56157 was detected. This vulnerability allows attackers to perform a cross-site scripting (XSS) attack by injecting malicious code into CSV content, which is executed when importing the file. To address this issue, users should upgrade iTop to versions 3.1.3 or 3.2.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-56157.
Read more IT Business Management