Recent Advisories

Severity ID Title Vendor Product Date Type
Unknown ADV-8661

bSecure 1.3.7 – 1.7.9 – Missing Authorization to Unauthenticated Privilege Escalation via order_info REST Endpoint

CVE Details Basic Information Title bSecure 1.3.7 – 1.7.9 – Missing Authorization to Unauthenticated Privilege Escalation via order_inf...

N/A N/A NEWS
Unknown ADV-8660

Like & Share My Site <= 0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

CVE Details Basic Information Title Like & Share My Site

N/A N/A NEWS
Unknown ADV-8659

Latest Post Accordian Slider <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

CVE Details Basic Information Title Latest Post Accordian Slider

N/A N/A NEWS
Unknown ADV-8658

Orion Login with SMS <= 1.0.5 - Authenticated Bypass via Weak OTP

CVE Details Basic Information Title Orion Login with SMS

N/A N/A NEWS
Unknown ADV-8642

Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.2.8 - Unauthenticated Arbitrary File Deletion Triggered via Admin Form Submission Deletion

CVE Details Basic Information Title Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)

N/A N/A NEWS
Unknown ADV-8640

CVE-2025-52580

CVE Details Basic Information Title CVE-2025-52580 Type cve Published 2025-07-22T04:49:33.459Z Modified 2025-07-22T04:49:33.459Z Product Informatio...

N/A N/A NEWS
Unknown ADV-8639

Sanluan PublicCMS viewer.html redirect

CVE Details Basic Information Title Sanluan PublicCMS viewer.html redirect Type cve Published 2025-07-22T03:32:05.747Z Modified 2025-07-22T03:32:05...

N/A N/A NEWS
Unknown ADV-8638

Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE Details Basic Information Title Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portf...

N/A N/A NEWS
Unknown ADV-8637

WP-Members <= 3.5.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE Details Basic Information Title WP-Members

N/A N/A NEWS
Unknown ADV-8636

WP JobHunt <= 7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Account Deletion

CVE Details Basic Information Title WP JobHunt

N/A N/A NEWS