Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-64194 2 Thimpress, Wordpress 2 Eduma, Wordpress 2025-10-30 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma eduma allows Stored XSS.This issue affects Eduma: from n/a through <= 5.7.6.
CVE-2025-64195 2 Thimpress, Wordpress 2 Eduma, Wordpress 2025-10-30 7.6 High
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Eduma eduma allows PHP Local File Inclusion.This issue affects Eduma: from n/a through <= 5.7.6.
CVE-2025-39460 1 Thimpress 1 Eduma 2025-06-24 5.3 Medium
Missing Authorization vulnerability in ThimPress Eduma allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eduma: from n/a through 5.6.4.
CVE-2024-35697 1 Thimpress 1 Eduma 2024-11-21 7.1 High
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThimPress Eduma allows Reflected XSS.This issue affects Eduma: from n/a through 5.4.7.