WAFPlanet

CVE Database - 2025

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

24903
Matching CVEs
15562
Critical
25943
High
66770
High WAF Coverage

CVE-2025-66159

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in merkulove Walker for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Walker for Elementor: from n/a through 1.1.6.

Missing Authorization
WAF: Low

CVE-2025-66158

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in merkulove Gmaper for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gmaper for Elementor: from n/a through 1.0.9.

Missing Authorization
WAF: Low

CVE-2025-66157

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in merkulove Slider for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider for Elementor: from n/a through 1.0.10.

Missing Authorization
WAF: Low

CVE-2025-66156

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in merkulove Watcher for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watcher for Elementor: from n/a through 1.0.9.

Missing Authorization
WAF: Low

CVE-2025-66155

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in merkulove Questionar for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Questionar for Elementor: from n/a through 1.1.7.

Missing Authorization
WAF: Low

CVE-2025-66154

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in merkulove Couponer for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Couponer for Elementor: from n/a through 1.1.7.

Missing Authorization
WAF: Low

CVE-2025-63038

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.40.

Missing Authorization
WAF: Low

CVE-2025-63021

UNKNOWN
0.00 CVSS none

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetipi Valenti Engine allows DOM-Based XSS.This issue affects Valenti Engine: from n/a through 1.0.3.

Cross-Site Scripting (XSS)
WAF: High

CVE-2025-62874

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Alexander AnyComment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyComment: from n/a through 0.3.6.

Missing Authorization
WAF: Low

CVE-2025-62123

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Ink themes WP Gmail SMTP allows Cross Site Request Forgery.This issue affects WP Gmail SMTP: from n/a through 1.0.7.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-62115

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in ThemeBoy Hide Plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through 1.0.4.

Missing Authorization
WAF: Low

CVE-2025-62113

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in emendo_seb Co-marquage service-public.Fr allows Cross Site Request Forgery.This issue affects Co-marquage service-public.Fr: from n/a through 0.5.77.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-62101

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Omid Shamloo Pardakht Delkhah allows Cross Site Request Forgery.This issue affects Pardakht Delkhah: from n/a through 3.0.0.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-62099

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Approveme Signature Add-On for Gravity Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Signature Add-On for Gravity Forms: from n/a through 1.8.6.

Missing Authorization
WAF: Low

CVE-2025-62088

UNKNOWN
0.00 CVSS none

Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: from n/a through 1.0.7.

Server-Side Request Forgery (SSRF)
WAF: Medium

CVE-2025-62078

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Upload Files During Checkout: from n/a through 3.0.0.

Missing Authorization
WAF: Low

CVE-2025-59138

UNKNOWN
0.00 CVSS none

Server-Side Request Forgery (SSRF) vulnerability in Jthemes Genemy allows Server Side Request Forgery.This issue affects Genemy: from n/a through 1.6.6.

Server-Side Request Forgery (SSRF)
WAF: Medium

CVE-2025-49339

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Digages Direct Payments WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Direct Payments WP: from n/a through 1.3.0.

Missing Authorization
WAF: Low

CVE-2019-25262

LOW
3.50 CVSS 3.1

A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This affects an unknown part of the file Chattify/send.php of the component Chat Message Handler. Such manipulation of the argument msg leads to cross site scripting. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The name of the patch is 995dd89d0e3ec5522966724be23a5d58ca1bdac3. Applying a patch is advised to resolve this issue. This vulnerability only affects products that are no longer supported by the maintainer.

Cross-Site Scripting (XSS) Code Injection
WAF: High

CVE-2025-63040

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Post Snippets allows Cross Site Request Forgery.This issue affects Post Snippets: from n/a through 4.0.11.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-63014

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Serhii Pasyuk Gmedia Photo Gallery allows Cross Site Request Forgery.This issue affects Gmedia Photo Gallery: from n/a through 1.24.1.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-63004

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Skynet Technologies USA LLC All in One Accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All in One Accessibility: from n/a through 1.14.

Missing Authorization
WAF: Low

CVE-2025-62755

UNKNOWN
0.00 CVSS none

Unauthenticated Broken Access Control in GS Portfolio for Envato <= 1.4.2 versions.

Missing Authorization
WAF: Low

CVE-2025-62751

HIGH
8.80 CVSS 3.1

Missing Authorization vulnerability in Extend Themes Vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through 1.0.24.

Missing Authorization
WAF: Low

CVE-2025-62747

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Aum Watcharapon Featured Image Generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Image Generator: from n/a through 1.3.3.

Missing Authorization
WAF: Low

CVE-2025-62154

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Recorp AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One: from n/a through 1.1.7.

Missing Authorization
WAF: Low

CVE-2025-62150

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Themesawesome History Timeline allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects History Timeline: from n/a through 1.0.6.

Missing Authorization
WAF: Low

CVE-2025-62148

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Eugen Bobrowski Robots.Txt rewrite allows Cross Site Request Forgery.This issue affects Robots.Txt rewrite: from n/a through 1.6.1.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-62133

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Manidoraisamy FormFacade allows Cross Site Request Forgery.This issue affects FormFacade: from n/a through 1.4.1.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-62132

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Strategy11 Team Tasty Recipes Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tasty Recipes Lite: from n/a through 1.1.5.

Missing Authorization
WAF: Low

CVE-2025-62131

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Strategy11 Team Tasty Recipes Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tasty Recipes Lite: from n/a through 1.1.5.

Missing Authorization
WAF: Low

CVE-2025-62130

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in WPdiscover Accordion Slider Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider Gallery: from n/a through 2.7.

Missing Authorization
WAF: Low

CVE-2025-62129

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Magnigenie RestroPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through 3.2.4.2.

Missing Authorization
WAF: Low

CVE-2025-62122

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Solwininfotech Trash Duplicate and 301 Redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trash Duplicate and 301 Redirect: from n/a through 1.9.1.

Missing Authorization
WAF: Low

CVE-2025-62116

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Quadlayers AI Copilot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Copilot: from n/a through 1.4.7.

Missing Authorization
WAF: Low

CVE-2025-62092

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Wiremo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wiremo: from n/a through 1.4.99.

Missing Authorization
WAF: Low

CVE-2025-62089

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack allows Cross Site Request Forgery.This issue affects Mergado Pack: from n/a through 4.2.0.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-62087

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through 1.2.4.

Missing Authorization
WAF: Low

CVE-2025-62084

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Imdad Next Web iNext Woo Pincode Checker allows Cross Site Request Forgery.This issue affects iNext Woo Pincode Checker: from n/a through 2.3.1.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-62080

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Channelize.Io Team Live Shopping & Shoppable Videos For WooCommerce allows Cross Site Request Forgery.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through 2.2.0.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-62079

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Damian WP Export Categories & Taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Export Categories &amp; Taxonomies: from n/a through 1.0.3.

Missing Authorization
WAF: Low

CVE-2025-59130

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Appointify allows Cross Site Request Forgery.This issue affects Appointify: from n/a through 1.0.8.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2025-49356

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Mykola Lukin Orders Chat for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Orders Chat for WooCommerce: from n/a through 1.2.0.

Missing Authorization
WAF: Low

CVE-2025-49338

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Flowbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flowbox: from n/a through 1.1.5.

Missing Authorization
WAF: Low

CVE-2025-15390

HIGH
8.80 CVSS 3.1

A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

Missing Authorization Incorrect Authorization
WAF: Low

CVE-2025-63031

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in WP Grids EasyTest allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EasyTest: from n/a through 1.0.1.

Missing Authorization
WAF: Low

CVE-2025-63022

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Illia Simple Like Page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Like Page: from n/a through 1.5.3.

Missing Authorization
WAF: Low

CVE-2025-63016

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Quadlayers QuadLayers TikTok Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QuadLayers TikTok Feed: from n/a through 4.6.4.

Missing Authorization
WAF: Low

CVE-2025-63001

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in nicdark Hotel Booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Booking: from n/a through 3.8.

Missing Authorization
WAF: Low

CVE-2025-62888

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Marco Milesi WP Attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attachments: from n/a through 5.2.

Missing Authorization
WAF: Low
Page 2 of 499 (24903 CVEs)