<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Composer</title>
  <link>https://cvedaily.com/pages/tags/composer.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/composer.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Composer</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-8134 – Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8134</guid>
    <pubDate>Thu, 21 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8134</strong></p>
  <p>Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code i…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34216 – CtrlPanel is open-source billing software for hosting providers. In versions 1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34216</guid>
    <pubDate>Tue, 19 May 2026 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34216</strong></p>
  <p>CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpoint accepted a fully qualified class name directly from user-supplied request input and used it for dynamic static method calls and object instantiation without any allowlist validation, allowing for authenticated Remote Code Execution. An authenticated admin-level user cou…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40261 – Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40261</guid>
    <pubDate>Wed, 15 Apr 2026 21:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40261</strong></p>
  <p>Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplie…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40176 – Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40176</guid>
    <pubDate>Wed, 15 Apr 2026 21:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40176</strong></p>
  <p>Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious co…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39712 – Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39712</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39712</strong></p>
  <p>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in tagDiv tagDiv Composer td-composer allows Code Injection.This issue affects tagDiv Composer: from n/a through <= 5.4.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39692 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39692</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39692</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Stored XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50001 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50001</guid>
    <pubDate>Thu, 19 Mar 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50001</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27968 – Packistry is a self-hosted Composer repository designed to handle PHP package di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27968</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27968</strong></p>
  <p>Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but did not enforce token expiration. As a result, an expired deploy token with the correct ability could still access repository endpoints (e.g., Composer metadata/download APIs). The fix in version 0.13.0…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69390 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69390</guid>
    <pubDate>Fri, 20 Feb 2026 16:22:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69390</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Business Template Blocks for WPBakery (Visual Composer) Page Builder templates-and-addons-for-wpbakery-page-builder allows Reflected XSS.This issue affects Business Template Blocks for WPBakery (Visual Composer) Page Builder: from n/a through <= 1.3.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25326 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25326</guid>
    <pubDate>Thu, 19 Feb 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25326</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23547 – Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23547</guid>
    <pubDate>Thu, 19 Feb 2026 09:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23547</strong></p>
  <p>Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CMSMasters Content Composer: from n/a through <= 2.5.8.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1426 – The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Obje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1426</guid>
    <pubDate>Wed, 18 Feb 2026 15:18:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1426</strong></p>
  <p>The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortcode_check function within the Live Composer compatibility layer. This makes it possible for authenticated attackers, with Author-level access and above, to inject a PHP Object. No known POP chain is present i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24739 – Symfony is a PHP framework for web and console applications and a set of reusabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24739</guid>
    <pubDate>Wed, 28 Jan 2026 21:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24739</strong></p>
  <p>Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not correctly treat some characters (notably `=`) as “special” when escaping arguments on Windows. When PHP is executed from an MSYS2-based environment (e.g. Git Bash) and Symfony Process spawns native Windo…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23593 – A vulnerability in the web-based management interface of HPE Aruba Networking Fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23593</guid>
    <pubDate>Tue, 27 Jan 2026 18:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23593</strong></p>
  <p>A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23592 – Insecure file operations in HPE Aruba Networking Fabric Composerâ€™s backup func...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23592</guid>
    <pubDate>Tue, 27 Jan 2026 18:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23592</strong></p>
  <p>Insecure file operations in HPE Aruba Networking Fabric Composerâ€™s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24594 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24594</guid>
    <pubDate>Fri, 23 Jan 2026 15:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24594</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for WPBakery Page Builder addons-for-visual-composer allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through <= 3.9.4.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50005 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50005</guid>
    <pubDate>Thu, 22 Jan 2026 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50005</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30631 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30631</guid>
    <pubDate>Tue, 06 Jan 2026 21:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30631</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Sales Funnel Builder, AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows Reflected XSS.This issue affects Woocommerce Sales Funnel Builder: from n/a through 1.1; Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Compose…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30628 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30628</guid>
    <pubDate>Wed, 31 Dec 2025 20:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30628</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows SQL Injection.This issue affects Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer): from n/a through 1.2.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67746 – Composer is a dependency manager for PHP. In versions on the 2.x branch prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67746</guid>
    <pubDate>Tue, 30 Dec 2025 16:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67746</strong></p>
  <p>Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in the terminal output of various Composer commands, causing mangled output and potentially leading to confusion or DoS of the terminal application. There is no proven exploit and this…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68598 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68598</guid>
    <pubDate>Wed, 24 Dec 2025 13:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68598</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.1.13.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68574 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68574</guid>
    <pubDate>Wed, 24 Dec 2025 13:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68574</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows DOM-Based XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14071 – The Live Composer – Free WordPress Website Builder plugin for WordPress is vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14071</guid>
    <pubDate>Sun, 21 Dec 2025 03:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14071</strong></p>
  <p>The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerabl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13537 – The Live Composer – Free WordPress Website Builder plugin for WordPress is vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13537</guid>
    <pubDate>Wed, 17 Dec 2025 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13537</strong></p>
  <p>The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scripting vulnerabilities via DOM manipulation in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68113 – ALTCHA is privacy-first software for captcha and bot protection. A cryptographic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68113</guid>
    <pubDate>Tue, 16 Dec 2025 01:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68113</strong></p>
  <p>ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind challenge parameters to the nonce, allowing an attacker to reinterpret a valid proof-of-work submission with a modified expiration value. This may allow previous…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-115</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14119 – The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14119</guid>
    <pubDate>Fri, 12 Dec 2025 04:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14119</strong></p>
  <p>The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'atvc_video_play' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and abo…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-13828 – SummaryA non privileged user can install and remove arbitrary packages via compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13828</guid>
    <pubDate>Tue, 02 Dec 2025 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-13828</strong></p>
  <p>SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.  ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62031 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62031</guid>
    <pubDate>Thu, 06 Nov 2025 16:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62031</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer.This issue affects tagDiv Composer: from n/a through <= 5.4.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62030 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62030</guid>
    <pubDate>Thu, 06 Nov 2025 16:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62030</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer.This issue affects tagDiv Composer: from n/a through <= 5.4.1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9552 – Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9552</guid>
    <pubDate>Fri, 10 Oct 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9552</strong></p>
  <p>Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58055 – Discourse is an open-source community discussion platform. In versions 3.5.0 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58055</guid>
    <pubDate>Wed, 01 Oct 2025 19:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58055</strong></p>
  <p>Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t authorized to access. By modifying the “topic_id” value in API requests to the AI suggestion endpoints, users could target specific restricted topics…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-50369 – In the Linux kernel, the following vulnerability has been resolved:

drm/vkms: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50369</guid>
    <pubDate>Wed, 17 Sep 2025 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50369</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/vkms: Fix null-ptr-deref in vkms_release()  A null-ptr-deref is triggered when it tries to destroy the workqueue in vkms->output.composer_workq in vkms_release().   KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]  CPU: 5 PID: 17193 Comm: modprobe Not tainted 6.0.0-11331-gd465bff130bf #24  RIP: 0010:des…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53564 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53564</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53564</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Builder Addon lbg_radio_player_addon_visual_composer allows Reflected XSS.This issue affects HTML5 Radio Player - WPBakery Page Builder Addon: from n/a through <= 2.5.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53562 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53562</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53562</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg_universal_video_player_addon_visual_composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53559 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53559</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53559</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53299 – Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visua...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53299</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53299</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer allows Object Injection.This issue affects ThemeMakers Visual Content Composer: from n/a through <= 1.5.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48170 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48170</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48170</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48154 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48154</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48154</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder lbg_vp_youtube_vimeo_addon_visual_composer allows Reflected XSS.This issue affects Multimedia Playlist Slider Addon for WPBakery Page Builder: from n/a through <= 2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55709 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55709</guid>
    <pubDate>Thu, 14 Aug 2025 19:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55709</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through < 45.15.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30626 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30626</guid>
    <pubDate>Thu, 14 Aug 2025 11:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30626</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder lbg_vp_youtube_vimeo_addon_visual_composer allows Reflected XSS.This issue affects Multimedia Playlist Slider Addon for WPBakery Page Builder: from n/a through <= 2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6572 – The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6572</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6572</guid>
    <pubDate>Fri, 08 Aug 2025 06:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6572</strong></p>
  <p>The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6572">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4414 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4414</guid>
    <pubDate>Fri, 04 Jul 2025 12:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4414</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through < 2.5.7.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-42977 – SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability cause...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-42977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-42977</guid>
    <pubDate>Tue, 10 Jun 2025 01:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-42977</strong></p>
  <p>SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. This allows an attacker to read or modify arbitrary files, resulting in a high impact on confidentiality and a low impact on integrity.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-42977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48276 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48276</guid>
    <pubDate>Mon, 19 May 2025 15:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48276</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through <= 45.11.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47280 – Umbraco Forms is a form builder that integrates with the Umbraco content managem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47280</guid>
    <pubDate>Tue, 13 May 2025 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47280</strong></p>
  <p>Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch and prior to versions 13.4.2 and 15.1.2, the 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address, potentia…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-42999 – SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-42999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-42999</guid>
    <pubDate>Tue, 13 May 2025 01:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-42999</strong></p>
  <p>SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-42999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2806 – The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2806</guid>
    <pubDate>Thu, 08 May 2025 12:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2806</strong></p>
  <p>The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into per…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47659 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47659</guid>
    <pubDate>Wed, 07 May 2025 15:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47659</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows Stored XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3510 – The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3510</guid>
    <pubDate>Fri, 02 May 2025 04:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3510</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute wheneve…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31324 – SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31324</guid>
    <pubDate>Thu, 24 Apr 2025 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31324</strong></p>
  <p>SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-46484 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46484</guid>
    <pubDate>Thu, 24 Apr 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-46484</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nasir179125 Image Hover Effects For WPBakery Page Builder image-hover-effects-for-visual-composer allows DOM-Based XSS.This issue affects Image Hover Effects For WPBakery Page Builder: from n/a through <= 2.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-46254 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46254</guid>
    <pubDate>Tue, 22 Apr 2025 10:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-46254</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through <= 45.10.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13645 – The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13645</guid>
    <pubDate>Fri, 04 Apr 2025 06:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13645</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. This makes it possible for unauthenticated attackers to Instantiate a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1705 – The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1705</guid>
    <pubDate>Fri, 28 Mar 2025 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1705</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation within the td_ajax_get_views AJAX action. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2804 – The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2804</guid>
    <pubDate>Fri, 28 Mar 2025 06:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2804</strong></p>
  <p>The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the 'account_id' and 'account_username' parameters in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succ…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2573 – The Amazing service box Addons For WPBakery Page Builder (formerly Visual Compos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2573</guid>
    <pubDate>Wed, 26 Mar 2025 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2573</strong></p>
  <p>The Amazing service box Addons For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in p…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13537 – The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13537</guid>
    <pubDate>Fri, 21 Feb 2025 04:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13537</strong></p>
  <p>The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin containing a publicly accessible composer-setup.php file with error display enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is n…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13592 – The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13592</guid>
    <pubDate>Wed, 19 Feb 2025 08:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13592</strong></p>
  <p>The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the 'team-builder-vc' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in tho…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13591 – The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13591</guid>
    <pubDate>Wed, 19 Feb 2025 08:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13591</strong></p>
  <p>The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'team-builder-vc' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and abo…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13582 – The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13582</guid>
    <pubDate>Tue, 18 Feb 2025 05:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13582</strong></p>
  <p>The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribut…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13535 – The Actionwear products sync plugin for WordPress is vulnerable to Full Path Dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13535</guid>
    <pubDate>Tue, 18 Feb 2025 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13535</strong></p>
  <p>The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.2. This is due the composer-setup.php file being publicly accessible with 'display_errors' set to true. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displa…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23057 – A vulnerability in the web management interface of HPE Aruba Networking Fabric C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23057</guid>
    <pubDate>Tue, 28 Jan 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23057</strong></p>
  <p>A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23056 – A vulnerability in the web management interface of HPE Aruba Networking Fabric C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23056</guid>
    <pubDate>Tue, 28 Jan 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23056</strong></p>
  <p>A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23055 – A vulnerability in the web management interface of HPE Aruba Networking Fabric C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23055</guid>
    <pubDate>Tue, 28 Jan 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23055</strong></p>
  <p>A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23054 – A vulnerability in the web-based management interface of HPE Aruba Networking Fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23054</guid>
    <pubDate>Tue, 28 Jan 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23054</strong></p>
  <p>A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not allowed by their privilege level. Successful exploitation could allow an attacker to manipulate user generated files, potentially leading to unauthorized changes in critical system configurations.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23053 – A privilege escalation vulnerability exists in the web-based management interfac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23053</guid>
    <pubDate>Tue, 28 Jan 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23053</strong></p>
  <p>A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23775 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23775</guid>
    <pubDate>Thu, 16 Jan 2025 21:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23775</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WWP GMAPS for WPBakery Page Builder Free gmaps-for-visual-composer-free allows Stored XSS.This issue affects GMAPS for WPBakery Page Builder Free: from n/a through <= 1.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-10175 – The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10175</guid>
    <pubDate>Wed, 27 Nov 2024 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-10175</strong></p>
  <p>The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wdo_pricing_tables shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-10172 – The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10172</guid>
    <pubDate>Thu, 21 Nov 2024 11:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-10172</strong></p>
  <p>The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's void_wbwhmcse_laouts_search shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51629 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51629</guid>
    <pubDate>Sat, 09 Nov 2024 14:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51629</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MetricThemes Header Footer Composer for Elementor header-footer-composer allows DOM-Based XSS.This issue affects Header Footer Composer for Elementor: from n/a through <= 1.0.4.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21264 – Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21264</guid>
    <pubDate>Tue, 15 Oct 2024 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21264</strong></p>
  <p>Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects.  Successful attacks of this vulnerability can resu…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7963 – The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7963</guid>
    <pubDate>Wed, 09 Oct 2024 02:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7963</strong></p>
  <p>The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45965 – Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45965</guid>
    <pubDate>Wed, 02 Oct 2024 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45965</strong></p>
  <p>Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47049 – The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47049</guid>
    <pubDate>Tue, 17 Sep 2024 14:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47049</strong></p>
  <p>The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5212 – The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5212</guid>
    <pubDate>Sat, 31 Aug 2024 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5212</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the on_ajax_register_forum_user function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-3886 – The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3886</guid>
    <pubDate>Sat, 31 Aug 2024 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-3886</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the on_ajax_check_envato_code function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43263 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43263</guid>
    <pubDate>Sun, 18 Aug 2024 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43263</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Visual Composer Visual Composer Starter allows Stored XSS.This issue affects Visual Composer Starter: from n/a through 3.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43320 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43320</guid>
    <pubDate>Sun, 18 Aug 2024 15:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43320</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder addons-for-visual-composer allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.9.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7414 – The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7414</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7414</strong></p>
  <p>The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.116. This is due to the plugin allowing direct access to the composer-setup.php file which has display_errors on.  This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The informat…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5709 – The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5709</guid>
    <pubDate>Tue, 06 Aug 2024 06:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5709</strong></p>
  <p>The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and with post permissions granted by an Administrator, to include and execute arbitrary files on the server, allowing the execution of any PHP code…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5708 – The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5708</guid>
    <pubDate>Tue, 06 Aug 2024 06:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5708</strong></p>
  <p>The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, and with post permissions granted by an Administrator, to inject arbitrary web scripts in…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6566 – The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6566</guid>
    <pubDate>Sat, 27 Jul 2024 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6566</strong></p>
  <p>The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due the plugin not preventing direct access to the composer-setup.php file which also has display_errors enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attack…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6554 – The Branda – White Label WordPress, Custom Login Page Customizer plugin for Word...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6554</guid>
    <pubDate>Thu, 11 Jul 2024 04:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6554</strong></p>
  <p>The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attack…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35768 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35768</guid>
    <pubDate>Fri, 21 Jun 2024 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35768</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.1.11.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35779 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35779</guid>
    <pubDate>Fri, 21 Jun 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35779</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35780 – Deserialization of Untrusted Data vulnerability in Live Composer Team Page Build...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35780</guid>
    <pubDate>Wed, 19 Jun 2024 11:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35780</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-3814 – The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3814</guid>
    <pubDate>Sat, 15 Jun 2024 02:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-3814</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whe…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3814">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3813 – The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3813</guid>
    <pubDate>Sat, 15 Jun 2024 02:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3813</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5265 – The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5265</guid>
    <pubDate>Thu, 13 Jun 2024 07:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5265</strong></p>
  <p>The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute within the vc_single_image shortcode in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35242 – Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35242</guid>
    <pubDate>Mon, 10 Jun 2024 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35242</strong></p>
  <p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially c…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35241 – Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35241</guid>
    <pubDate>Mon, 10 Jun 2024 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35241</strong></p>
  <p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installin…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35653 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35653</guid>
    <pubDate>Tue, 04 Jun 2024 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35653</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer.This issue affects Visual Composer Website Builder: from n/a through <= 45.8.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-3888 – The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3888</guid>
    <pubDate>Tue, 04 Jun 2024 05:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-3888</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execu…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32957 – Missing Authorization vulnerability in Live Composer Team Page Builder: Live Com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32957</guid>
    <pubDate>Fri, 26 Apr 2024 11:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32957</strong></p>
  <p>Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.38.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32560 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32560</guid>
    <pubDate>Thu, 18 Apr 2024 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32560</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sharabindu QR Code Composer allows Stored XSS.This issue affects QR Code Composer: from n/a through 2.0.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-31933 – Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Build...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31933</guid>
    <pubDate>Mon, 15 Apr 2024 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-31933</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.35.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32003 – wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32003</guid>
    <pubDate>Fri, 12 Apr 2024 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32003</strong></p>
  <p>wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of its testing framework to allow a browser environment (such as headless Chrome) to act as a user in the Backend or User plugin without having to go through authentication. This route is `[[URL]]/_dusk/login/[[USER ID]]/[[MANAGER]]` - where…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-30450 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30450</guid>
    <pubDate>Fri, 29 Mar 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-30450</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Step-Byte-Service GmbH OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) allows Stored XSS.This issue affects OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer): from n/a through 1.1.1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2725 – Information exposure vulnerability in the CIGESv2 system. A remote attacker migh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2725</guid>
    <pubDate>Fri, 22 Mar 2024 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2725</strong></p>
  <p>Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-2307 – A flaw was found in osbuild-composer. A condition can be triggered that disables...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2307</guid>
    <pubDate>Tue, 19 Mar 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-2307</strong></p>
  <p>A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2307">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
