In GDPR Cookie Compliance plugin for WordPress versions before 4.15.9 a low severity vulnerability CVE-2025-1624 was detected. This vulnerability allows attackers to perform Stored Cross-Site Scripting (XSS) attacks due to the plugin not sanitizing and escaping some of its settings, which could allow high privilege users such as admins to exploit it, even when the unfiltered_html capability is disallowed (e.g., in multisite setups). To address this issue, users should upgrade GDPR Cookie Compliance plugin to versions 4.15.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1624.
Read more CMSIn Mattermost Desktop App versions 5.10.0 and prior a low severity vulnerability CVE-2025-1398 was detected. This vulnerability allows attackers with remote access to bypass Transparency, Consent, and Control (TCC) via code injection due to explicitly declared unnecessary macOS entitlements. To address this issue, users should upgrade Mattermost to versions 5.11.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1398.
Read more CommunicationIn MongoDB C Driver library versions prior to 1.27.5 and MongoDB Server versions 8.0 prior to 8.0.1 and 7.0 prior to 7.0.16 a high severity vulnerability CVE-2025-0755 was detected. This vulnerability allows attackers to trigger a buffer overflow when handling BSON documents exceeding the maximum allowable size (INT32_MAX), potentially causing a segmentation fault and application crash. To address this issue, users should upgrade to libbson versions 1.27.5, MongoDB Server versions 8.0.1 or 7.0.16. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0755.
Read more DatabaseIn Tripetto plugin for WordPress versions up to and including 8.0.9 a medium severity vulnerability CVE-2025-1530 was detected. This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) due to missing nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary results by tricking a site administrator into performing an action such as clicking on a link. To address this issue, users should upgrade Tripetto plugin to versions 8.0.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1530.
Read more CMSIn Test Email Plugin for WordPress versions 1.1.8 and prior a high severity vulnerability CVE-2025-2325 was detected. This vulnerability allows unauthenticated attackers to exploit stored XSS via email logs due to insufficient sanitization and escaping, injecting arbitrary scripts that execute when users access the compromised page. To address this issue, users should upgrade WP Test Email plugin to versions 1.1.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2325.
Read more CMSIn Zoorum Comments plugin for WordPress versions up to and including 0.9 a medium severity vulnerability CVE-2025-2163 was detected. This vulnerability allows unauthenticated attackers to exploit CSRF due to missing or incorrect nonce validation in the zoorum_set_options() function, enabling them to update settings and inject malicious scripts by tricking a site administrator into clicking a link. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2163.
Read more CMSIn WP01 plugin for WordPress versions up to and including 2.6.2 a medium severity vulnerability CVE-2025-2267 was detected. This vulnerability allows authenticated attackers with Subscriber-level access and above to download arbitrary files from the server due to a missing capability check and insufficient restrictions on the make_archive() function. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2267.
Read more CMSIn Pixelstats plugin for WordPress versions up to and including 0.8.2 a medium severity vulnerability CVE-2025-2164 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via the ‘post_id’ and ‘sortby’ parameters due to insufficient input sanitization and output escaping, which execute when a user is tricked into performing an action like clicking on a link. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2164.
In GitLab EE versions 16.5 prior to 17.7.7, 17.8 prior to 17.8.5 and 17.9 prior to 17.9.2 a low severity vulnerability CVE-2024-7296 was detected. This vulnerability allows a user with custom permissions to approve pending membership requests beyond the maximum number of allowed users. To address this issue, users should upgrade GitLab EE to versions 17.7.7, 17.8.5 or 17.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7296.
Read more Developer Tools