CVE & Security Advisory Details

Dokploy Platform

CVE-2025-53376

HIGH

OS Command Injection

A critical OS command injection vulnerability was discovered in Dokploy that allows attackers to execute arbitrary system commands.

CVE-2025-53375

HIGH

Local File Inclusion

A local file inclusion vulnerability in Dokploy allows unauthorized access to sensitive files on the server.

CVE-2025-53374

MEDIUM

Information Disclosure

An information disclosure vulnerability in Dokploy exposes sensitive configuration and system information.

Cisco BroadWorks

CVE-2025-20307

MEDIUM

Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability in Cisco BroadWorks Application Delivery Platform could allow an attacker to execute arbitrary JavaScript code.

pfSense Security Advisories

pfSense-SA-25_07.webgui

HIGH

Stored XSS in Wake on LAN pages and Dashboard widget

A stored cross-site scripting vulnerability was discovered in pfSense's Wake on LAN pages and Dashboard widget.

pfSense-SA-25_06.webgui

HIGH

Stored XSS in IPsec Phase 1

A stored cross-site scripting vulnerability exists in the IPsec Phase 1 configuration of pfSense.

pfSense-SA-25_05.webgui

HIGH

Stored XSS in Firewall Schedules

A stored cross-site scripting vulnerability was identified in pfSense Firewall Schedules configuration.

OpenZiti

CVE-2025-27500

CRITICAL

Unauthenticated Stored XSS on admin panel

An unauthenticated stored cross-site scripting vulnerability in OpenZiti's admin panel allows remote attackers to execute arbitrary JavaScript.

CVE-2025-27501

CRITICAL

Unauthenticated SSRF on admin panel

An unauthenticated server-side request forgery (SSRF) vulnerability in OpenZiti's admin panel enables attackers to access internal resources.

WordPress Plugin Vulnerabilities

CVE-2023-4691

CRITICAL

Bookly <= 22.3.1 - Authenticated (Administrator+) SQL Injection

An authenticated SQL injection vulnerability in Bookly plugin versions up to 22.3.1 allows administrators to execute arbitrary SQL queries.

CVE-2023-4620

CRITICAL

Booking Calendar <= 9.7.3 - Unauthenticated Stored Cross-Site Scripting

An unauthenticated stored XSS vulnerability in Booking Calendar plugin allows attackers to inject malicious scripts.

CVE-2023-4490

CRITICAL

WP Job Portal <= 2.0.5 - Unauthenticated SQL Injection

An unauthenticated SQL injection vulnerability in WP Job Portal allows remote attackers to extract sensitive database information.

CVE-2023-4502

HIGH

GTranslate <= 3.0.3 - Authenticated (Administrator+) Cross-Site Scripting via Multiple Parameters

Multiple authenticated XSS vulnerabilities in GTranslate plugin allow administrators to inject malicious scripts.

CVE-2023-1465

MEDIUM

WP EasyPay <= 4.0.4 - Reflected Cross-Site Scripting

A reflected XSS vulnerability in WP EasyPay plugin allows attackers to execute JavaScript in user browsers.

CVE-2023-1546

MEDIUM

MyCryptoCheckout <= 2.123 - Reflected Cross-Site Scripting via URL

A reflected XSS vulnerability via URL parameters in MyCryptoCheckout plugin enables script injection attacks.

CVE-2023-1554

HIGH

Quick Paypal Payments <= 5.7.26.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

An authenticated stored XSS vulnerability in Quick Paypal Payments plugin allows administrators to persistently inject malicious scripts.