ZeroHour

Vulnerabilities

557 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18258
+4 in the same advisory: …18359 …18277 …18275 …18276
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote au

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset

NVD description · AI analysis pending
8.8
group max
<1%
  • escriptorium escriptorium
CVE-2019-25680
Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting m

Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database information including version details and other data.

NVD description · AI analysis pending
8.8<1% PoC
  • phpscriptsmall advance gift shop pro script
CVE-2019-25676
Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipul

Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view parameter in list-details.php to execute arbitrary code or extract database information.

NVD description · AI analysis pending
8.8<1% PoC
  • phpscriptsmall ask expert script
CVE-2019-25668
News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thr

News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information.

NVD description · AI analysis pending
8.8<1% PoC
  • phpscriptsmall news website script
CVE-2019-25527
+3 in the same advisory: …25525 …25528 …25526
Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the numguest parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloads to bypass authentication, extract sensitive data, or modify database contents.

NVD description · AI analysis pending
8.8<1% PoC
  • inoutscripts inout homestay
CVE-2019-25524
+3 in the same advisory: …25523 …25522 …25521
XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the

XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to bypass authentication, extract sensitive data, or modify database contents.

NVD description · AI analysis pending
8.8<1% PoC
  • xooscripts xoogallery
CVE-2019-25499
+4 in the same advisory: …25498 …25501 …25500 …25502
Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send POST requests to get_job_applications_ajax.php with malicious job_id values to bypass authentication, extract sensitive data, or modify database contents.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • simplejobscript simplejobscript
CVE-2026-3383
+2 in the same advisory: …3382 …3384
A weakness has been identified in ChaiScript up to 6.1.0.

A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the file include/chaiscript/dispatchkit/boxed_number.hpp. Executing a manipulation can lead to divide by zero. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

NVD description · AI analysis pending
1.9<1%
  • chaiscript chaiscript
CVE-2019-25444
+1 in the same advisory: …25445
Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thr

Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can supply malicious SQL syntax in the page parameter to extract sensitive database information or modify database contents.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • phpscriptsmall fiverr clone script
CVE-2026-2656
+1 in the same advisory: …2655
A flaw has been found in ChaiScript up to 6.1.0.

A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file include/chaiscript/dispatchkit/type_info.hpp. This manipulation causes use after free. The attack requires local access. The attack's complexity is rated as high. The exploitability is reported as difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD description · AI analysis pending
1.1<1% PoC ×2
  • chaiscript chaiscript
CVE-2026-25514
+1 in the same advisory: …25513
FacturaScripts is open-source enterprise resource planning and accounting software.

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection vulnerability in the autocomplete functionality that allows authenticated attackers to extract sensitive data from the database including user credentials, configuration settings, and all stored business data. The vulnerability exists in the CodeModel::all() method where user-supplied parameters are directly concatenated into SQL queries without sanitization or parameterized binding. This issue has been patched in version 2025.81.

NVD description · AI analysis pending
8.7
group max
<1% PoC
  • facturascripts facturascripts
CVE-2026-23997
+1 in the same advisory: …23476
FacturaScripts is open-source enterprise resource planning and accounting software.

FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity encoding. This allows an attacker to execute arbitrary JavaScript in the browser of viewing the history by administrators.

NVD description · AI analysis pending
9.0
group max
<1% PoC
  • facturascripts facturascripts
CVE-2021-47918
+2 in the same advisory: …47917 …47919
Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module.

Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web application.

NVD description · AI analysis pending
8.6
group max
<1% PoC
  • simplephpscripts simple cms php
CVE-2026-24783
soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts.

soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts. In versions 1.3.0 and 1.4.0, the `mulDiv(x, y, z)` function incorrectly handled cases where both the intermediate product $x * y$ and the divisor $z$ were negative. The logic assumed that if the intermediate product was negative, the final result must also be negative, neglecting the sign of $z$. This resulted in rounding being applied in the wrong direction for cases where both $x * y$ and $z$ were negative. The functions most at risk are `fixed_div_floor` and `fixed_div_ceil`, as they often use non-constant numbers as the divisor $z$ in `mulDiv`. This error is present in all signed `FixedPoint` and `SorobanFixedPoint` implementations, including `i64`, `i128`, and `I256`. Versions 1.3.1 and 1.4.1 contain a patch. No known workarounds for this issue are available.

NVD description · AI analysis pending
7.5<1%
  • script3 soroban-fixed-point-math
CVE-2025-69210
FacturaScripts is open-source enterprise resource planning and accounting software.

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cross-site scripting (XSS) vulnerability exists in the product file upload functionality. Authenticated users can upload crafted XML files containing executable JavaScript. These files are later rendered by the application without sufficient sanitization or content-type enforcement, allowing arbitrary JavaScript execution when the file is accessed. Because product files uploaded by regular users are visible to administrative users, this vulnerability can be leveraged to execute malicious JavaScript in an administrator’s browser session. Version 2025.7 fixes the issue.

NVD description · AI analysis pending
1.2<1%
  • facturascripts facturascripts
CVE-2025-9848
+1 in the same advisory: …9847
A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0.

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

NVD description · AI analysis pending
5.5
group max
<1% PoC
  • scriptandtools real estate management system
CVE-2025-4380
Unauthenticated Local File Inclusion in WordPress Ads Pro Plugin (≤ 4.89)

Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager, a WordPress plugin by scripteo, is vulnerable to an unauthenticated local file inclusion (CWE-98) affecting all versions up to and including 4.89. The flaw resides in the bsa_template parameter of the bsa_preview_callback function, which fails to properly restrict which files can be included, so a remote, unauthenticated attacker can supply a crafted path that causes the server to include and execute arbitrary local files. Any PHP code inside an included file runs in the web server's context, enabling attackers to bypass access controls, obtain sensitive data, and achieve code execution where attacker-controllable .php files can be uploaded or already exist on the site. Any WordPress site running the plugin at version 4.89 or earlier is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 40.4% EPSS score (99th percentile) indicates a high likelihood of exploitation within the next 30 days.

Do: Update the plugin to a patched release newer than version 4.89 as soon as one is available, or deactivate the plugin until the patch is applied. Since the flaw allows arbitrary file inclusion and potential code execution, check the site for unexpected .php uploads, modified files, and rogue administrator accounts, and review access logs for unauthenticated requests containing bsa_template parameters.

9.8
group max
40%
  • scripteo Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager (WordPress plugin) All versions up to and including 4.89 (no fixed version specified in the source data)
moderateroughly 20,000+ sites (plugin is listed with approximately 20k active installs on the WordPress.org directory)
CVE-2025-6329
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0.

A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of the argument ID leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • scriptandtools real estate management system
CVE-2025-5128
A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0.

A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of the component Admin Login Panel. The manipulation of the argument Password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.9<1% PoC
  • scriptandtools real estate management system
CVE-2024-13322
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD description · AI analysis pending
7.52%
  • scripteo ads pro
CVE-2025-4066
+1 in the same advisory: …4067
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0.

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/addpackage.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
6.9<1%
  • scriptandtools online traveling system