CVE Alert: CVE-2025-12879 - vinoth06 - User Generator and Importer - https://www.redpacketsecurity.com/cve-alert-cve-2025-12879-vinoth06-user-generator-and-importer/

#OSINT #ThreatIntel #CyberSecurity #cve-2025-12879 #vinoth06 #user-generator-and-importer

CVE Alert: CVE-2025-12879 - vinoth06 - User Generator and Importer - RedPacket Security

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing

RedPacket Security
CVE Alert: CVE-2025-14091 - TrippWasTaken - PHP-Guitar-Shop - RedPacket Security

A weakness has been identified in TrippWasTaken PHP-Guitar-Shop up to 6ce0868889617c1975982aae6df8e49555d0d555. This vulnerability affects unknown code of the

RedPacket Security
CVE Alert: CVE-2025-13614 - wpkube - Cool Tag Cloud - RedPacket Security

The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' shortcode in all versions up to, and

RedPacket Security

CVE Alert: CVE-2025-12851 - wphocus - My auctions allegro - https://www.redpacketsecurity.com/cve-alert-cve-2025-12851-wphocus-my-auctions-allegro/

#OSINT #ThreatIntel #CyberSecurity #cve-2025-12851 #wphocus #my-auctions-allegro

CVE Alert: CVE-2025-12851 - wphocus - My auctions allegro - RedPacket Security

The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller'

RedPacket Security
HackerOne Bug Bounty Disclosure: deck-app-allowed-user-with-can-share-permission-to-modify-permissions-of-other-non-owners-daroo - RedPacket Security

Company Name: Nextcloud

RedPacket Security
HackerOne Bug Bounty Disclosure: stored-xss-vulnerability-via-svg-file-aptroom - RedPacket Security

Company Name: Nextcloud

RedPacket Security
HackerOne Bug Bounty Disclosure: -nextcloud-tables-v-share-enumeration-without-authorization-regression-of-cve-x-doteth - RedPacket Security

Company Name: Nextcloud

RedPacket Security
HackerOne Bug Bounty Disclosure: calendar-attachments-of-local-files-are-offered-to-downloaded-daroo - RedPacket Security

Company Name: Nextcloud

RedPacket Security
HackerOne Bug Bounty Disclosure: tables-app-allowed-users-to-view-columns-metadata-information-of-any-table-daroo - RedPacket Security

Company Name: Nextcloud

RedPacket Security
HackerOne Bug Bounty Disclosure: unauthenticated-graphql-access-by-prepending-schema-to-private-operations-pwnie - RedPacket Security

Company Name: Enjin

RedPacket Security