In Mattermost Mobile Apps versions 2.25.0 and prior a medium severity vulnerability CVE-2025-1558 was detected. This vulnerability allows attackers to cause the Android application to crash by sending a message containing a maliciously crafted GIF due to improper validation prior to rendering. To address this issue, users should upgrade Mattermost Mobile Apps to versions 2.26.0, 2.25.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1558.
Read more CommunicationIn Digital License Manager plugin for WordPress versions up to and including 1.7.3 a medium severity vulnerability CVE-2025-2635 was detected. This vulnerability allows attackers to inject arbitrary web scripts via reflected cross-site scripting (XSS) by exploiting the improper use of the remove_query_arg() function without appropriate URL escaping, tricking users into performing actions such as clicking on a malicious link. To address this issue, users should upgrade Digital License Manager plugin to versions 1.7.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2635.
Read more CMSIn WP Church Donation plugin for WordPress versions 1.7 and prior a high severity vulnerability CVE-2024-13690 was detected. This vulnerability allows attackers to inject arbitrary web scripts via several donation form submission parameters, which execute whenever a user accesses the affected page due to insufficient input sanitization and output escaping. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13690.
Read more CMSIn teachPress plugin for WordPress versions 9.0.9 and prior a medium severity vulnerability CVE-2025-1320 was detected. This vulnerability allows attackers to delete imports via a forged request by exploiting missing or incorrect nonce validation on the import.php page, tricking site administrators into performing actions such as clicking on a malicious link. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1320.
Read more CMSIn DICOM Support plugin for WordPress versions 0.10.6 and prior a medium severity vulnerability CVE-2024-12623 was detected. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts via the plugin’s ‘dcm’ shortcode due to insufficient input sanitization and output escaping on user-supplied attributes, with the injected scripts executing whenever a user accesses the affected page. To address this issue, users should upgrade DICOM Support plugin to versions 0.10.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12623.
Read more CMSIn Next.js versions prior to 14.2.25 and 15.2.3 a critical severity vulnerability CVE-2025-29927 was detected. This vulnerability allows attackers to bypass authorization checks within a Next.js application if the authorization check occurs in middleware. To address this issue, users should upgrade Next.js to versions 14.2.25, 15.2.3, 15.3.0-canary.12 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-29927.
Read more Mobile App DevelopmentIn Kubernetes k8s.io/kubernetes/cmd/kube-apiserver package versions 1.3.0 up to and including 1.32.3 a low severity vulnerability CVE-2024-7598 was detected. This vulnerability allows attackers to bypass network restrictions enforced by network policies during namespace deletion, as the undefined order of object deletion may result in network policies being removed before the pods they protect, creating a brief window where network policies are not enforced. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7598.
Read more Developer ToolsIn Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, and 10.5.x <= 10.5.0 a high severity vulnerability CVE-2025-25068 was detected. This vulnerability allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes. To address this issue, users should upgrade Mattermost to versions 10.6.0, 10.4.3, 10.3.4, 9.11.9, 10.5.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-25068.
Read more CommunicationIn Liferay Portal versions 7.4.0 through 7.4.3.126 and Liferay DXP versions 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 a medium severity vulnerability CVE-2025-2565 was detected. This vulnerability allows unauthorized users to obtain entry data from forms. To address this issue, users should upgrade Liferay Portal to version 7.4.3.129, Liferay DXP to versions 2024.Q4.0, 2024.Q3.1 or 2024.Q1.13. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2565.
Read more CMS