CVE-2025-4128 Mattermost Guest User Information Disclosure Vulnerability

Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about pu ...

Continue Reading
CVE-2025-47950

creation_timestamp| type| source ---|---|--- 2025-06-11 12:17:31+00:00| seen|...Read More ...

Continue Reading
CVE-2025-32711

creation_timestamp| type| source ---|---|--- 2025-06-11 13:34:29+00:00| seen|...Read More ...

Continue Reading
CVE-2025-5144 The Events Calendar <= 6.13.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sa ...

Continue Reading
CVE-2025-5144

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sa ...

Continue Reading
CVE-2025-5144 The Events Calendar <= 6.13.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sa ...

Continue Reading
CVE-2025-5144 The Events Calendar <= 6.13.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sa ...

Continue Reading
CVE-2025-29756

creation_timestamp| type| source ---|---|--- 2025-06-11 11:17:44+00:00| seen|...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: