Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1.2 CVE-2025-69210

FacturaScripts vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload_CVE-2025-69210

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cross-site scripting (XSS) vu...

NeoRazorX facturascripts < 2025.7 CVE
LOW 1.3 CVE-2025-67746

Composer vulnerable to ANSI sequence injection_CVE-2025-67746

Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Compos...

composer composer >= 2.0, < 2.2.26 CVE
LOW 3.8 CVE-2025-69015

WordPress Crowdsignal Forms plugin <= 1.7.2 - Broken Access Control vulnerability_CVE-2025-69015

Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Secur...

Automattic Crowdsignal Forms n/a CVE
LOW 2.3 CVE-2025-15242

PHPEMS Coupon race condition_CVE-2025-15242

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing manipula...

n/a PHPEMS 11.0 CVE
LOW 2.3 CVE-2025-15222

Dromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserialization_CVE-2025-15222

A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSeriali...

Dromara Sa-Token 1.0 CVE
LOW 2.3 CVE-2025-15141

Halo Configuration actuator information disclosure_CVE-2025-15141

A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configurati...

n/a Halo 2.21.0 CVE
LOW 2.3 CVE-2025-15124

JeecgBoot list getParameterMap improper authorization_CVE-2025-15124

A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The m...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15125

JeecgBoot queryDepartPermission improper authorization_CVE-2025-15125

A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepar...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15126

JeecgBoot getPositionUserList improper authorization_CVE-2025-15126

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/positi...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15120

JeecgBoot getDeptRoleList improper authorization_CVE-2025-15120

A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manip...

n/a JeecgBoot 3.0 CVE