Post

2025-09-30 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2024-5200Unknown - PostieThe Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).CNA n/a CVSS3.1: 6.1 - MEDIUM0Exploitation: pocAutomatable: noTechnical Impact: partialPostie < 1.9.71 - Admin+ Stored XSSgithub
CVE-2021-21311vrana - adminerAdminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.CVSS3.1: 7.2 - HIGH0 1 2 3 4Exploitation: activeAutomatable: yesTechnical Impact: partialSSRF in adminergithub
CVE-2025-10341Perfex CRM - Perfex CRMHTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameter ‘company’ at the endpoint ‘/clients/client/x.CVSS4.0: 5.3 - MEDIUM0Exploitation: noneAutomatable: yesTechnical Impact: partialHTML injection in Perfex CRMgithub
This post is licensed under CC BY 4.0 by the author.