VulnSea

Daily digest

Saturday 13 December 2025

A quiet day: only 7 new CVEs against a recent average of about 56. Severity skewed high: 1 critical and 3 high, 57% of the total.

7
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2025-10738Critical· 9.8
9mo ago

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ parameter in all versions up to, and including, 3.0.7 due to insufficient escaping on the user supplied parameter and lack o…

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ parameter in all versions up to, and including, 3.0.7 due to insufficient escaping on the user supplied parameter and lack o…

▾ MidnightEPSS 0.41%via NVD
CVE-2025-13094High· 8.8
9mo ago

The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in all versions up to, and including, 1.0.7

The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in all versions up to, and including, 1.0.7. This makes it possible for au…

▾ TwilightEPSS 0.50%via NVD
CVE-2025-14475High· 8.1
9mo ago

The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.1 via the `extensive_vc_get_module_template_part` function

The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.1 via the `extensive_vc_get_module_template_part` function. This is due to insufficien…

▾ TwilightEPSS 0.63%via NVD
CVE-2025-14542High· 7.5
9mo ago

Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification

Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification

▾ Twilightutcp · utcpEPSS 0.26%via OSV
CVE-2025-8780Medium· 6.4
9mo ago

The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero Header and Pricing Table widgets in all versions up to, and including, 3.9.1 due to insufficient input sanitization a…

The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero Header and Pricing Table widgets in all versions up to, and including, 3.9.1 due to insufficient input sanitization a…

▾ SunlitEPSS 0.22%via NVD
CVE-2025-14586Medium· 6.3
9mo ago

A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224

A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os comm…

▾ Sunlittotolink · x5000r_firmwareEPSS 2.8%via NVD
CVE-2025-12109Medium· 6.4
9mo ago

The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the script adder present in posts in all versions up to, and including, 2.0.5 due to insufficient…

The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the script adder present in posts in all versions up to, and including, 2.0.5 due to insufficient…

▾ SunlitEPSS 0.22%via NVD

Most-affected vendors

By CVEs published in the period.