Daily digest
Sunday 30 November 2025
A heavy day: 14 new CVEs, well above the recent average of about 4. Of those, 4 high.
New this day, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2025-13792High· 7.3A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97
A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros …
CVE-2025-13788High· 7.3A vulnerability has been found in Chanjet CRM up to 20251106
A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. The manipulation of the argument gblOrgID leads to sql injection. The attack can be initia…
CVE-2025-13786High· 7.3A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665
A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content results in code injection. It is possible…
CVE-2025-66423High· 7.1trytond does not enforce access rights for the route of the HTML editor.
trytond does not enforce access rights for the route of the HTML editor.
CVE-2025-66424Medium· 6.5Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
CVE-2025-13791Medium· 6.3A vulnerability was identified in Scada-LTS up to 2.7.8.1
A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversa…
CVE-2025-13789Medium· 6.3A vulnerability was found in ZenTao up to 21.7.6-8564
A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remote…
CVE-2025-13787Medium· 5.4A flaw has been found in ZenTao up to 21.7.6-8564
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper pr…
CVE-2025-66422Medium· 4.3trytond allows remote attackers to obtain sensitive trace-back (server setup) information
trytond allows remote attackers to obtain sensitive trace-back (server setup) information
CVE-2025-13793Medium· 4.3A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e
A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter …
CVE-2025-13790Medium· 4.3A vulnerability was determined in Scada-LTS up to 2.7.8.1
A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be ut…
CVE-2025-13785Medium· 4.3A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5
A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the file /user/profile of the component Image Handler. Such manipulation leads to informatio…
Most-affected vendors
By CVEs published in the period.