🛡 Cybersecurity & Privacy 🛡 - CVEs
前往频道在 Telegram
🔐 Explore the latest CVEs in cybersecurity and privacy. 🔔 Daily updates. 💻 Ensuring your online security. 📩 lalilolalo.dev@gmail.com
显示更多431
订阅者
无数据24 小时
无数据7 天
-330 天
数据加载中...
相似频道
标签云
进出提及
---
---
---
---
---
---
吸引订阅者
八月 '25
八月 '25
+4
在0个频道中
七月 '25
+7
在0个频道中
Get PRO
六月 '25
+5
在0个频道中
Get PRO
五月 '25
+10
在0个频道中
Get PRO
四月 '25
+33
在0个频道中
Get PRO
三月 '25
+29
在0个频道中
Get PRO
二月 '25
+34
在0个频道中
Get PRO
一月 '25
+48
在1个频道中
Get PRO
十二月 '24
+25
在2个频道中
Get PRO
十一月 '24
+37
在2个频道中
Get PRO
十月 '24
+17
在1个频道中
Get PRO
九月 '24
+41
在1个频道中
Get PRO
八月 '24
+34
在2个频道中
Get PRO
七月 '24
+30
在0个频道中
Get PRO
六月 '24
+29
在0个频道中
Get PRO
五月 '24
+163
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 15 八月 | 0 | |||
| 14 八月 | +1 | |||
| 13 八月 | 0 | |||
| 12 八月 | 0 | |||
| 11 八月 | 0 | |||
| 10 八月 | 0 | |||
| 09 八月 | 0 | |||
| 08 八月 | 0 | |||
| 07 八月 | +2 | |||
| 06 八月 | +1 | |||
| 05 八月 | 0 | |||
| 04 八月 | 0 | |||
| 03 八月 | 0 | |||
| 02 八月 | 0 | |||
| 01 八月 | 0 |
频道帖子
‼️ CVE-2025-8464 ‼️
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7guestuserid cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the originally intended directory. The impact of this vulnerability is limited, as file types are validated and only safe ones can be uploaded, while deletion is limited to the plugin's uploads folder.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs| 2 | ‼️ CVE-2025-7499 ‼️
The BetterDocs Advanced AIDriven Documentation, FAQ Knowledge Base Tool for Elementor Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getresponse function in all versions up to and including 4.1.1. This makes it possible for unauthenticated attackers to retrieve passwords for passwordprotected documents as well as the metadata of private and draft documents.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 4 |
| 3 | ‼️ CVE-2025-8898 ‼️
The Taxi Booking Manager for Woocommerce Ecab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin not properly validating a user's capabilities prior to updating a plugin setting or their identity prior to updating their details like email address. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 4 | ‼️ CVE-2025-8896 ‼️
The User Profile Builder Beautiful User Registration Forms, User Profiles User Role Editor plugin for WordPress is vulnerable to Stored CrossSite Scripting via the 'gdprcommunicationpreferences' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriberlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the GDPR Communication Preferences module is enabled and at least one GDPR Communication Preferences field has been added to the edit profile form.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 5 | ‼️ CVE-2025-8089 ‼️
The Advanced iFrame plugin for WordPress is vulnerable to Stored CrossSite Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 6 | ‼️ CVE-2025-8113 ‼️
The Ebook Store WordPress plugin before 5.8015 does not escape the SERVER'REQUESTURI' parameter before outputting it back in an attribute, which could lead to Reflected CrossSite Scripting in old web browsers.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 7 | ‼️ CVE-2025-38501 ‼️
In the Linux kernel, the following vulnerability has been resolved ksmbd limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 8 | ‼️ CVE-2025-8293 ‼️
The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored CrossSite Scripting via the date parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 9 | ‼️ CVE-2025-7686 ‼️
The weichuncaiWP plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the smoptions.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 10 | ‼️ CVE-2025-7684 ‼️
The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the 'lastfmalbumsartwork.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 11 | ‼️ CVE-2025-7683 ‼️
The LatestCheckins plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1. This is due to missing or incorrect nonce validation on the 'LatestCheckins' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 12 | ‼️ CVE-2025-7668 ‼️
The Linux Promotional Plugin plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'inuxpromotionalplugin.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 13 | ‼️ CVE-2025-7664 ‼️
The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the checkactivatepermission permission callback for the wpjsonpresslearnv1activate REST API endpoint in all versions up to, and including, 1.0.2. The callback reads the clientsupplied Origin header and, after parsing, allows the request if it matches one of the trusted domains, without ever verifying user authentication, capabilities, or nonce tokens. This makes it possible for unauthenticated attackers to activate premium features by simply spoofing the Origin header.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 14 | ‼️ CVE-2025-7651 ‼️
The Earnware Connect plugin for WordPress is vulnerable to Stored CrossSite Scripting via the plugin's 'ewhasrole' shortcode in all versions up to, and including, 1.0.73 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 15 | ‼️ CVE-2025-7649 ‼️
The Surbma Recent Comments Shortcode plugin for WordPress is vulnerable to Stored CrossSite Scripting via the plugin's 'recentcomments' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 16 | ‼️ CVE-2025-7441 ‼️
The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs through the wpjsonstorychiefwebhook RESTAPI endpoint that does not have sufficient filetype validation. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 17 | ‼️ CVE-2025-7440 ‼️
The Anber Elementor Addon plugin for WordPress is vulnerable to Stored CrossSite Scripting via the item'buttonlink''url' parameter in all versions up to, and including, 1.0.1 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 18 | ‼️ CVE-2025-7439 ‼️
Anber Elementor Addon plugin for WordPress is vulnerable to Stored CrossSite Scripting via the anberitem'buttonlink''url' parameter in all versions up to, and including, 1.0.1 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 19 | ‼️ CVE-2025-6221 ‼️
The Embed Bokun plugin for WordPress is vulnerable to Stored CrossSite Scripting via the align parameter in all versions up to, and including, 0.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
| 20 | ‼️ CVE-2025-6080 ‼️
The WPGYM Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities prior to adding users. This makes it possible for authenticated attackers, with Subscriberlevel access and above, to create new users, including admins.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs | 1 |
