CROWD-SOURCED
VULNERABILITIES DATABASE
RingCentral Communications (Authentication Bypass) < 1.7.0
27 Aug 2025
PROTECTED
Vibes (SQL Injection via `resource` Parameter) < 2.2.1
25 Aug 2025
PROTECTED
Dokan Pro (Privilege Escalation) < 4.0.6
25 Aug 2025
PROTECTED
Event List (Privilege Escalation) < 2.0.5
25 Aug 2025
PROTECTED
Kipso (Unauthenticated Local File Inclusion) < 1.3.5
23 Aug 2025
PROTECTED
Simpler Checkout (Authentication Bypass) < 1.1.10
22 Aug 2025
PROTECTED
Wptobe-memberships (Arbitrary File Deletion)
22 Aug 2025
PROTECTED
Event Manager, Events Calendar, Booking, Registrations and Tickets - Eventin (Server-Side Request Forgery) < 4.0.38
22 Aug 2025
PROTECTED
Case Theme User (Authentication Bypass via Social Login) < 1.0.4
22 Aug 2025
PROTECTED
Bravis User (Authentication Bypass to Account Takeover) < 1.0.1
22 Aug 2025
PROTECTED
Inspiro (Cross-Site Request Forgery) < 2.1.3
20 Aug 2025
PROTECTED
WP Webhooks (Unauthenticated Arbitrary File Copy) < 3.3.6
20 Aug 2025
PROTECTED
Redirection for Contact Form 7 (Unauthenticated Arbitrary File Deletion) < 3.2.5
19 Aug 2025
PROTECTED
Redirection for Contact Form 7 (Unauthenticated PHP Object Injection) < 3.2.5
19 Aug 2025
PROTECTED
Real Spaces - WordPress Properties Directory Theme (Privilege Escalation) < 3.6
18 Aug 2025
PROTECTED
Cloudflare Image Resizing (Remote Code Execution) < 1.5.7
18 Aug 2025
PROTECTED
JS Archive List (Unauthenticated SQL Injection) < 6.1.6
18 Aug 2025
PROTECTED
ServerBuddy by PluginBuddy.com (Cross-Site Request Forgery)
16 Aug 2025
PROTECTED
Soledad (Unauthenticated Arbitrary Shortcode Execution) < 8.6.8
15 Aug 2025
PROTECTED
Taxi Booking Manager for Woocommerce | E-cab (Privilege Escalation) < 1.3.1
15 Aug 2025
PROTECTED
Crowdsourced Patches for Crowdsourced Vulnerabilities.
© 2026. All rights reserved.