🛡 Cybersecurity & Privacy 🛡 - CVEs
الذهاب إلى القناة على Telegram
🔐 Explore the latest CVEs in cybersecurity and privacy. 🔔 Daily updates. 💻 Ensuring your online security. 📩 lalilolalo.dev@gmail.com
إظهار المزيد431
المشتركون
لا توجد بيانات24 ساعات
لا توجد بيانات7 أيام
-330 أيام
جاري تحميل البيانات...
القنوات المماثلة
سحابة العلامات
الإشارات الواردة والصادرة
---
---
---
---
---
---
جذب المشتركين
أغسطس '25
أغسطس '25
+4
في 0 قنوات
يوليو '25
+7
في 0 قنوات
Get PRO
يونيو '25
+5
في 0 قنوات
Get PRO
مايو '25
+10
في 0 قنوات
Get PRO
أبريل '25
+33
في 0 قنوات
Get PRO
مارس '25
+29
في 0 قنوات
Get PRO
فبراير '25
+34
في 0 قنوات
Get PRO
يناير '25
+48
في 1 قنوات
Get PRO
ديسمبر '24
+25
في 2 قنوات
Get PRO
نوفمبر '24
+37
في 2 قنوات
Get PRO
أكتوبر '24
+17
في 1 قنوات
Get PRO
سبتمبر '24
+41
في 1 قنوات
Get PRO
أغسطس '24
+34
في 2 قنوات
Get PRO
يوليو '24
+30
في 0 قنوات
Get PRO
يونيو '24
+29
في 0 قنوات
Get PRO
مايو '24
+163
في 0 قنوات
| التاريخ | نمو المشتركين | الإشارات | القنوات | |
| 15 أغسطس | 0 | |||
| 14 أغسطس | +1 | |||
| 13 أغسطس | 0 | |||
| 12 أغسطس | 0 | |||
| 11 أغسطس | 0 | |||
| 10 أغسطس | 0 | |||
| 09 أغسطس | 0 | |||
| 08 أغسطس | 0 | |||
| 07 أغسطس | +2 | |||
| 06 أغسطس | +1 | |||
| 05 أغسطس | 0 | |||
| 04 أغسطس | 0 | |||
| 03 أغسطس | 0 | |||
| 02 أغسطس | 0 | |||
| 01 أغسطس | 0 |
منشورات القناة
‼️ CVE-2025-8464 ‼️
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7guestuserid cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the originally intended directory. The impact of this vulnerability is limited, as file types are validated and only safe ones can be uploaded, while deletion is limited to the plugin's uploads folder.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs| 2 | ‼️ CVE-2025-7499 ‼️
The BetterDocs Advanced AIDriven Documentation, FAQ Knowledge Base Tool for Elementor Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getresponse function in all versions up to and including 4.1.1. This makes it possible for unauthenticated attackers to retrieve passwords for passwordprotected documents as well as the metadata of private and draft documents.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 4 |
| 3 | ‼️ CVE-2025-8898 ‼️
The Taxi Booking Manager for Woocommerce Ecab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin not properly validating a user's capabilities prior to updating a plugin setting or their identity prior to updating their details like email address. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 4 | ‼️ CVE-2025-8896 ‼️
The User Profile Builder Beautiful User Registration Forms, User Profiles User Role Editor plugin for WordPress is vulnerable to Stored CrossSite Scripting via the 'gdprcommunicationpreferences' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriberlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the GDPR Communication Preferences module is enabled and at least one GDPR Communication Preferences field has been added to the edit profile form.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 5 | ‼️ CVE-2025-8089 ‼️
The Advanced iFrame plugin for WordPress is vulnerable to Stored CrossSite Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 6 | ‼️ CVE-2025-8113 ‼️
The Ebook Store WordPress plugin before 5.8015 does not escape the SERVER'REQUESTURI' parameter before outputting it back in an attribute, which could lead to Reflected CrossSite Scripting in old web browsers.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 7 | ‼️ CVE-2025-38501 ‼️
In the Linux kernel, the following vulnerability has been resolved ksmbd limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 8 | ‼️ CVE-2025-8293 ‼️
The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored CrossSite Scripting via the date parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 9 | ‼️ CVE-2025-7686 ‼️
The weichuncaiWP plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the smoptions.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 10 | ‼️ CVE-2025-7684 ‼️
The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the 'lastfmalbumsartwork.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 11 | ‼️ CVE-2025-7683 ‼️
The LatestCheckins plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1. This is due to missing or incorrect nonce validation on the 'LatestCheckins' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 12 | ‼️ CVE-2025-7668 ‼️
The Linux Promotional Plugin plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'inuxpromotionalplugin.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 13 | ‼️ CVE-2025-7664 ‼️
The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the checkactivatepermission permission callback for the wpjsonpresslearnv1activate REST API endpoint in all versions up to, and including, 1.0.2. The callback reads the clientsupplied Origin header and, after parsing, allows the request if it matches one of the trusted domains, without ever verifying user authentication, capabilities, or nonce tokens. This makes it possible for unauthenticated attackers to activate premium features by simply spoofing the Origin header.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 14 | ‼️ CVE-2025-7651 ‼️
The Earnware Connect plugin for WordPress is vulnerable to Stored CrossSite Scripting via the plugin's 'ewhasrole' shortcode in all versions up to, and including, 1.0.73 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 15 | ‼️ CVE-2025-7649 ‼️
The Surbma Recent Comments Shortcode plugin for WordPress is vulnerable to Stored CrossSite Scripting via the plugin's 'recentcomments' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 16 | ‼️ CVE-2025-7441 ‼️
The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs through the wpjsonstorychiefwebhook RESTAPI endpoint that does not have sufficient filetype validation. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 17 | ‼️ CVE-2025-7440 ‼️
The Anber Elementor Addon plugin for WordPress is vulnerable to Stored CrossSite Scripting via the item'buttonlink''url' parameter in all versions up to, and including, 1.0.1 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 18 | ‼️ CVE-2025-7439 ‼️
Anber Elementor Addon plugin for WordPress is vulnerable to Stored CrossSite Scripting via the anberitem'buttonlink''url' parameter in all versions up to, and including, 1.0.1 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 19 | ‼️ CVE-2025-6221 ‼️
The Embed Bokun plugin for WordPress is vulnerable to Stored CrossSite Scripting via the align parameter in all versions up to, and including, 0.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 20 | ‼️ CVE-2025-6080 ‼️
The WPGYM Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities prior to adding users. This makes it possible for authenticated attackers, with Subscriberlevel access and above, to create new users, including admins.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
