Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
Recent vulnerabilities and exploits
7.1
CVSSv3
CVE-2025-48146
Cross-Site Request Forgery (CSRF) vulnerability in Michael Lups SEO Flow by LupsOnline allows Stored XSS. This issue affects SEO Flow by LupsOnline: from n/a up to and including 2.2.0.
Michael Lups Seo Flow By Lupsonline
7.1
CVSSv3
CVE-2025-48144
Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce allows Stored XSS. This issue affects Import Export For WooCommerce: from n/a up to and including 1.6.2.
Sidngr Import Export For Woocommerce
4.3
CVSSv3
CVE-2025-48138
Missing Authorization vulnerability in berthaai BERTHA AI allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BERTHA AI: from n/a up to and including 1.12.11.
Berthaai Bertha Ai
7.5
CVSSv3
CVE-2025-48136
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik allows PHP Local File Inclusion. This issue affects Mortgage Calculator Estatik: from n/a up to and including 2.0...
Estatik Mortgage Calculator Estatik
8.5
CVSSv3
CVE-2025-48137
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview allows SQL Injection. This issue affects Interview: from n/a up to and including 1.01.
Proxymis Interview
6.5
CVSSv3
CVE-2025-48135
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptivada for WP allows DOM-Based XSS. This issue affects Aptivada for WP: from n/a up to and including 2.0.0.
Aptivadadev Aptivada For Wp
7.2
CVSSv3
CVE-2025-48134
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs allows Object Injection. This issue affects WP Tabs: from n/a up to and including 2.2.11.
Shapedplugin Llc Wp Tabs
6.5
CVSSv3
CVE-2025-48132
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor allows Stored XSS. This issue affects X Addons for Elementor: from n/a up to and including 1.0.14.
Pencilwp X Addons For Elementor
6.5
CVSSv3
CVE-2025-48131
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam UltraAddons Elementor Lite allows Stored XSS. This issue affects UltraAddons Elementor Lite: from n/a up to and including 2.0.0.
Saiful Islam Ultraaddons Elementor Lite
4.3
CVSSv3
CVE-2025-48128
Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sharespine Woocommerce Connector: from n/a up to and including 4.7.55.
Sharespine Sharespine Woocommerce Connector
Preferred Score:
CVSSv2
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
CVE-2025-48117
themovation
CVE-2025-47556
CVE-2025-4794
log injection
privilege
CVE-2025-4427
rozario
shout
CVE-2025-48138
css3 compare pricing tables for wordpress
CVE-2023-21563
malicious code
on">CVE-2025-48114
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »