uz
Feedback
🛡 Cybersecurity & Privacy 🛡 - CVEs

🛡 Cybersecurity & Privacy 🛡 - CVEs

Kanalga Telegram’da o‘tish

🔐 Explore the latest CVEs in cybersecurity and privacy. 🔔 Daily updates. 💻 Ensuring your online security. 📩 lalilolalo.dev@gmail.com

Ko'proq ko'rsatish
Buy Ad
431
Obunachilar
Ma'lumot yo'q24 soatlar
Ma'lumot yo'q7 kun
-330 kun
Obunachilarni jalb qilish
Avgust '25
Avgust '25
+4
0 kanalda
Iyul '25
+7
0 kanalda
Get PRO
Iyun '25
+5
0 kanalda
Get PRO
May '25
+10
0 kanalda
Get PRO
Aprel '25
+33
0 kanalda
Get PRO
Mart '25
+29
0 kanalda
Get PRO
Fevral '25
+34
0 kanalda
Get PRO
Yanvar '25
+48
1 kanalda
Get PRO
Dekabr '24
+25
2 kanalda
Get PRO
Noyabr '24
+37
2 kanalda
Get PRO
Oktabr '24
+17
1 kanalda
Get PRO
Sentabr '24
+41
1 kanalda
Get PRO
Avgust '24
+34
2 kanalda
Get PRO
Iyul '24
+30
0 kanalda
Get PRO
Iyun '24
+29
0 kanalda
Get PRO
May '24
+163
0 kanalda
Sana
Obunachilarni jalb qilish
Esdaliklar
Kanallar
15 Avgust0
14 Avgust+1
13 Avgust0
12 Avgust0
11 Avgust0
10 Avgust0
09 Avgust0
08 Avgust0
07 Avgust+2
06 Avgust+1
05 Avgust0
04 Avgust0
03 Avgust0
02 Avgust0
01 Avgust0
Kanal postlari
‼️ CVE-2025-8464 ‼️ The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7guestuserid cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the originally intended directory. The impact of this vulnerability is limited, as file types are validated and only safe ones can be uploaded, while deletion is limited to the plugin's uploads folder. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

2
‼️ CVE-2025-7499 ‼️ The BetterDocs Advanced AIDriven Documentation, FAQ Knowledge Base Tool for Elementor Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getresponse function in all versions up to and including 4.1.1. This makes it possible for unauthenticated attackers to retrieve passwords for passwordprotected documents as well as the metadata of private and draft documents. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
4
3
‼️ CVE-2025-8898 ‼️ The Taxi Booking Manager for Woocommerce Ecab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin not properly validating a user's capabilities prior to updating a plugin setting or their identity prior to updating their details like email address. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
4
‼️ CVE-2025-8896 ‼️ The User Profile Builder Beautiful User Registration Forms, User Profiles User Role Editor plugin for WordPress is vulnerable to Stored CrossSite Scripting via the 'gdprcommunicationpreferences' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriberlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the GDPR Communication Preferences module is enabled and at least one GDPR Communication Preferences field has been added to the edit profile form. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
5
‼️ CVE-2025-8089 ‼️ The Advanced iFrame plugin for WordPress is vulnerable to Stored CrossSite Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
6
‼️ CVE-2025-8113 ‼️ The Ebook Store WordPress plugin before 5.8015 does not escape the SERVER'REQUESTURI' parameter before outputting it back in an attribute, which could lead to Reflected CrossSite Scripting in old web browsers. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
7
‼️ CVE-2025-38501 ‼️ In the Linux kernel, the following vulnerability has been resolved ksmbd limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
8
‼️ CVE-2025-8293 ‼️ The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored CrossSite Scripting via the date parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
9
‼️ CVE-2025-7686 ‼️ The weichuncaiWP plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the smoptions.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
10
‼️ CVE-2025-7684 ‼️ The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the 'lastfmalbumsartwork.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
11
‼️ CVE-2025-7683 ‼️ The LatestCheckins plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1. This is due to missing or incorrect nonce validation on the 'LatestCheckins' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
12
‼️ CVE-2025-7668 ‼️ The Linux Promotional Plugin plugin for WordPress is vulnerable to CrossSite Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'inuxpromotionalplugin.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
13
‼️ CVE-2025-7664 ‼️ The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the checkactivatepermission permission callback for the wpjsonpresslearnv1activate REST API endpoint in all versions up to, and including, 1.0.2. The callback reads the clientsupplied Origin header and, after parsing, allows the request if it matches one of the trusted domains, without ever verifying user authentication, capabilities, or nonce tokens. This makes it possible for unauthenticated attackers to activate premium features by simply spoofing the Origin header. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
14
‼️ CVE-2025-7651 ‼️ The Earnware Connect plugin for WordPress is vulnerable to Stored CrossSite Scripting via the plugin's 'ewhasrole' shortcode in all versions up to, and including, 1.0.73 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
15
‼️ CVE-2025-7649 ‼️ The Surbma Recent Comments Shortcode plugin for WordPress is vulnerable to Stored CrossSite Scripting via the plugin's 'recentcomments' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
16
‼️ CVE-2025-7441 ‼️ The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs through the wpjsonstorychiefwebhook RESTAPI endpoint that does not have sufficient filetype validation. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
17
‼️ CVE-2025-7440 ‼️ The Anber Elementor Addon plugin for WordPress is vulnerable to Stored CrossSite Scripting via the item'buttonlink''url' parameter in all versions up to, and including, 1.0.1 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
18
‼️ CVE-2025-7439 ‼️ Anber Elementor Addon plugin for WordPress is vulnerable to Stored CrossSite Scripting via the anberitem'buttonlink''url' parameter in all versions up to, and including, 1.0.1 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
19
‼️ CVE-2025-6221 ‼️ The Embed Bokun plugin for WordPress is vulnerable to Stored CrossSite Scripting via the align parameter in all versions up to, and including, 0.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1
20
‼️ CVE-2025-6080 ‼️ The WPGYM Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities prior to adding users. This makes it possible for authenticated attackers, with Subscriberlevel access and above, to create new users, including admins. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs
1