Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-27925 | Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input. Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-13632 | The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross- The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. NVD description · AI analysis pending | 7.1 | <1% | PoC |
| — | |
| CVE-2022-38167 | The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS. The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2018-12529 +1 in the same advisory: …12528 | An issue was discovered on Intex N150 devices. An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user passwords and router settings. NVD description · AI analysis pending | 8.8 group max | <1% | PoC ×3 |
| — |