ZeroHour

Vulnerabilities

62 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-3218
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XS

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2.

NVD description · AI analysis pending
4.8<1%
  • pixelite responsive favicons
CVE-2026-28274
+2 in the same advisory: …28275 …28276
Initiative is a self-hosted project management platform.

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user with upload permissions within the "Initiatives" section can upload a malicious `.html` or `.htm` file as a document. Because the uploaded HTML file is served under the application's origin without proper sandboxing, the embedded JavaScript executes in the context of the application. As a result, authentication tokens, session cookies, or other sensitive data can be exfiltrated to an attacker-controlled server. Additionally, since the uploaded file is hosted under the application's domain, simply sharing the direct file link may result in execution of the malicious script when accessed. Version 0.32.4 fixes the issue.

NVD description · AI analysis pending
8.7
group max
<1% PoC
  • morelitea initiative
CVE-2025-68547
Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Configured Access Control Security Levels.Thi

Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Follow My Blog Post: from n/a through <= 2.4.0.

NVD description · AI analysis pending
7.5<1%
  • wpwebelite follow my blog post
CVE-2025-64258
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Retrieve Embedd

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Retrieve Embedded Sensitive Data.This issue affects Follow My Blog Post: from n/a through <= 2.3.9.

NVD description · AI analysis pending
7.5<1%
  • wpwebelite follow my blog post
CVE-2025-52287
OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

NVD description · AI analysis pending
8.8<1% PoC
  • elite project elite
CVE-2025-6970
+2 in the same advisory: …6975 …6976
Unauthenticated Time-Based SQL Injection in Events Manager WordPress Plugin

The Events Manager plugin for WordPress (all versions up to and including 7.0.3) contains a time-based SQL injection (CWE-89) in the 'orderby' parameter, caused by insufficient escaping of user-supplied input and inadequate preparation of the existing SQL query. An unauthenticated attacker can submit a crafted 'orderby' value to append additional SQL queries into existing ones and use time-based techniques (delays in responses) to infer results. Successful exploitation allows extraction of sensitive information from the site's database, with no privileges or user interaction required (CVSS 7.5 High, high confidentiality impact). Any WordPress site running Events Manager 7.0.3 or earlier is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the high EPSS score of 65.6% (99th percentile) indicates a substantial likelihood of exploitation within the next 30 days.

Do: Update Events Manager to the latest patched release (anything newer than 7.0.3) as soon as possible, prioritizing internet-facing sites. Until patched, apply a WAF rule or virtual patch that restricts or sanitizes the 'orderby' parameter on Events Manager endpoints, and review web logs and database activity for signs of time-based injection attempts or data extraction.

7.5
group max
66%
  • pixelite Events Manager – Calendar, Bookings, Tickets, and more! (WordPress plugin) All versions up to and including 7.0.3
large≈100,000+ WordPress sites (plugin has roughly 100k+ active installs)
CVE-2025-39472
Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooComme

Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a through < 2.8.3.

NVD description · AI analysis pending
8.8<1%
  • wpwebelite woocommerce social login
CVE-2024-11260
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in al

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD description · AI analysis pending
7.5<1%
  • pixelite events manager
CVE-2024-56265
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers al

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9.

NVD description · AI analysis pending
6.1<1%
  • wpwebelite woocommerce pdf vouchers
CVE-2024-54383
Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommer

Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9.

NVD description · AI analysis pending
9.81%
  • wpwebelite woocommerce pdf vouchers
CVE-2024-10114
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7.

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

NVD description · AI analysis pending
8.1<1%
  • wpwebelite woocommerce social login
CVE-2024-39650
Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W

Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouchers: from n/a through 4.9.4.

NVD description · AI analysis pending
9.8<1%
  • wpwebelite woocommerce pdf vouchers
CVE-2024-43132
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / W

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.

NVD description · AI analysis pending
9.8<1%
  • wpwebelite docket
CVE-2024-43131
Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained b

Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.

NVD description · AI analysis pending
7.5<1%
  • wpwebelite docket
CVE-2024-39651
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This iss

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.

NVD description · AI analysis pending
9.3<1%
  • wpwebelite woocommerce pdf vouchers
CVE-2024-7503
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5.

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the userID. This requires the email module to be enabled.

NVD description · AI analysis pending
9.8<1%
  • wpwebelite woocommerce social login
CVE-2024-39652
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflect

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.

NVD description · AI analysis pending
6.1<1%
  • wpwebelite woocommerce pdf vouchers
CVE-2024-6636
+2 in the same advisory: …6635 …6637
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_e

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator while registering for an account.

NVD description · AI analysis pending
9.8
group max
<1%
  • wpwebelite woocommerce social login
CVE-2024-37502
Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login:

Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3.

NVD description · AI analysis pending
7.5<1%
  • wpwebelite woocommerce social login
CVE-2024-5889
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

NVD description · AI analysis pending
6.1<1%
  • pixelite events manager
CVE-2024-5871
+1 in the same advisory: …5868
The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of unt

The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

NVD description · AI analysis pending
9.8
group max
<1%
  • wpwebelite woocommerce social login
CVE-2024-3492
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'locatio

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4<1%
  • pixelite events manager
CVE-2024-30515
Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager:

Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.

NVD description · AI analysis pending
8.8<1%
  • pixelite events manager
CVE-2024-2111
+1 in the same advisory: …2110
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4
group max
<1%
  • pixelite events manager
CVE-2024-0614
The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to ins

The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

NVD description · AI analysis pending
4.8<1% PoC
  • pixelite events manager
CVE-2022-40361
Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.

Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.

NVD description · AI analysis pending
6.1<1%
  • elitecms elite cms
CVE-2023-48326
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue af

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.

NVD description · AI analysis pending
6.1<1%
  • pixelite events manager
CVE-2023-42331
A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.

A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.

NVD description · AI analysis pending
8.81% PoC ×3
  • elitecms elite cms
CVE-2023-28701
ELITE TECHNOLOGY CORP.

ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to perform arbitrary system commands, disrupt service or terminate service.

NVD description · AI analysis pending
9.8<1%
  • elite webfax
CVE-2022-3891
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the

The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.

NVD description · AI analysis pending
5.3<1% PoC
  • pixelite wp fullcalendar
CVE-2022-30808
elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.

elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.

NVD description · AI analysis pending
9.8
group max
17% PoC
  • elitecms elite cms
CVE-2022-24222
+3 in the same advisory: …24221 …24220 …24219
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.

NVD description · AI analysis pending
9.81% PoC
  • elitecms elite cms