CVE tracker
312 subscribers
4.41K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-52159 - WordPress PPress Default Configuration Hardcoded Credentials Vulnerability

CVE ID : CVE-2025-52159
Published : Sept. 19, 2025, 8:15 p.m. | 52 minutes ago
Description : Hardcoded credentials in default configuration of PPress 0.0.9.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54761 - "PPress Session Cookie Privilege Escalation Vulnerability"

CVE ID : CVE-2025-54761
Published : Sept. 19, 2025, 8:15 p.m. | 52 minutes ago
Description : An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54815 - PPress SSTI Code Injection Vulnerability

CVE ID : CVE-2025-54815
Published : Sept. 19, 2025, 8:15 p.m. | 52 minutes ago
Description : Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-56762 - Paracrawl KeOPs XSS

CVE ID : CVE-2025-56762
Published : Sept. 19, 2025, 8:15 p.m. | 52 minutes ago
Description : Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57396 - Tandoor Recipes Privilege Escalation Vulnerability

CVE ID : CVE-2025-57396
Published : Sept. 19, 2025, 8:15 p.m. | 52 minutes ago
Description : Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in the User Profile API Endpoint containing two boolean values indicating whether a user is staff or administrative. Consequently, any user can escalate their privileges to the highest level.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-59431 - MapServer - WFS XML Filter Query SQL injection

CVE ID : CVE-2025-59431
Published : Sept. 19, 2025, 8:15 p.m. | 52 minutes ago
Description : MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It seems like expression checking is bypassed by introducing double quote characters in the PropertyName. Allowing to manipulate backend database queries. This vulnerability is fixed in 8.4.1.
Severity: 8.9 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-59689 - Libraesva ESG Command Injection Vulnerability

CVE ID : CVE-2025-59689
Published : Sept. 19, 2025, 8:15 p.m. | 52 minutes ago
Description : Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9079 - Admin RCE via prepackaged plugins by way of misconfigured imports directory

CVE ID : CVE-2025-9079
Published : Sept. 19, 2025, 8:15 p.m. | 52 minutes ago
Description : Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows admin users to execute arbitrary code via malicious plugin upload to prepackaged plugins directory
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9081 - IDOR in board file download allows any user to download any file by UUID

CVE ID : CVE-2025-9081
Published : Sept. 19, 2025, 8:15 p.m. | 52 minutes ago
Description : Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43808 - Liferay Portal Commerce Virtual Product Information Disclosure

CVE ID : CVE-2025-43808
Published : Sept. 19, 2025, 8:37 p.m. | 30 minutes ago
Description : The Commerce component in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions saves virtual products uploaded to Documents and Media with guest view permission, which allows remote attackers to access and download virtual products for free via a crafted URL.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10652 - Robcore Netatmo <= 1.7 - Authenticated (Contributor+) SQL Injection via robcore-netatmo Shortcode

CVE ID : CVE-2025-10652
Published : Sept. 20, 2025, 1:53 a.m. | 3 hours, 16 minutes ago
Description : The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore-netatmo shortcode in all versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10181 - WordPress Draft List Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-10181
Published : Sept. 20, 2025, 7:08 a.m. | 2 hours, 3 minutes ago
Description : The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10305 - WordPress Secure Passkeys Unauthorized Access

CVE ID : CVE-2025-10305
Published : Sept. 20, 2025, 7:08 a.m. | 2 hours, 3 minutes ago
Description : The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_passkey() and passkeys_list() function in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and delete passkeys.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9949 - WordPress Internal Links Manager CSRF Vulnerability

CVE ID : CVE-2025-9949
Published : Sept. 20, 2025, 7:08 a.m. | 2 hours, 3 minutes ago
Description : The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the link deletion functionality in the process_bulk_action() function. This makes it possible for unauthenticated attackers to delete SEO links via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10489 - "WordPress SureForms Drag and Drop Contact Form Builder Unauthenticated Form Creation Vulnerability"

CVE ID : CVE-2025-10489
Published : Sept. 20, 2025, 7:08 a.m. | 2 hours, 3 minutes ago
Description : The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to create forms when the user interface specifically prohibits it.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10002 - WordPress ClickWhale Link Manager SQL Injection Vulnerability

CVE ID : CVE-2025-10002
Published : Sept. 20, 2025, 7:08 a.m. | 2 hours, 3 minutes ago
Description : The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection via the export_csv() function in all versions up to, and including, 2.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This may be exploitable by lower level users if access to the plugin is granted.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10658 - SupportCandy WordPress Plugin Authentication Bypass Vulnerability

CVE ID : CVE-2025-10658
Published : Sept. 20, 2025, 9:10 a.m. | 4 hours, 1 minute ago
Description : The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. This is due to missing rate limiting on the OTP verification for guest login. This makes it possible for unauthenticated attackers to bypass authentication and gain unauthorized access to customer support tickets by brute forcing the 6-digit OTP code.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9883 - WordPress Browser Sniff CSRF

CVE ID : CVE-2025-9883
Published : Sept. 20, 2025, 9:10 a.m. | 4 hours, 1 minute ago
Description : The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9882 - osTicket WP Bridge WordPress CSRF

CVE ID : CVE-2025-9882
Published : Sept. 20, 2025, 9:10 a.m. | 4 hours, 1 minute ago
Description : The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9887 - WordPress Custom Login And Signup Widget CSRF Vulnerability

CVE ID : CVE-2025-9887
Published : Sept. 20, 2025, 9:10 a.m. | 4 hours, 1 minute ago
Description : The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation in the /frndzk_adminclsw.php file. This makes it possible for unauthenticated attackers to change the email and username settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10741 - Selleo Mentingo Unrestricted Upload Vulnerability

CVE ID : CVE-2025-10741
Published : Sept. 20, 2025, 3:09 p.m. | 2 hours, 5 minutes ago
Description : A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown function of the component Profile Picture Handler. The manipulation of the argument userAvatar leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...