Vulnerabilities with Nuclei Scanner Templates
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2025-11693
9.8
CRITICAL
NUCLEI
EPSS 0.17
Export WP Page to Static HTML & PDF <4.3.4 - Info Disclosure
The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.4 through publicly exposed cookies.txt files containing authentication cookies. This makes it possible for unauthenticated attackers to cookies that may have been injected into the log file if the site administrator triggered a back-up using a specific user role like 'administrator.'
CWE-200
Dec 13, 2025
CVE-2025-10897
8.6
HIGH
NUCLEI
EPSS 0.23
WooCommerce Designer Pro <1.9.28 - Info Disclosure
The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.
CWE-22
Oct 31, 2025
CVE-2025-59582
5.3
MEDIUM
NUCLEI
EPSS 0.01
Ajax Load More <7.6.0.2 - Info Disclosure
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Darren Cooney Ajax Load More ajax-load-more allows Retrieve Embedded Sensitive Data.This issue affects Ajax Load More: from n/a through <= 7.6.0.2.
CWE-497
Sep 22, 2025
CVE-2025-62039
7.5
HIGH
NUCLEI
EPSS 0.03
AYS Pro AI ChatBot - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Retrieve Embedded Sensitive Data.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.6.6.
CWE-201
Nov 06, 2025
CVE-2025-1361
7.5
HIGH
NUCLEI
EPSS 0.08
Ip2location Country Blocker < 2.38.9 - Missing Authorization
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.
CWE-862
Feb 22, 2025
CVE-2025-59341
HIGH
1 Writeup
NUCLEI
EPSS 0.02
Esm-dev Esm.sh - Path Traversal
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the server to read and return files from the host filesystem (or other unintended file sources).
CWE-23
Sep 17, 2025
CVE-2025-23211
9.9
CRITICAL
1 Writeup
NUCLEI
EPSS 0.68
Tandoor Recipes <1.5.24 - RCE
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.
CWE-1336
Jan 28, 2025
CVE-2025-49002
9.8
CRITICAL
3 PoCs
Analysis
NUCLEI
EPSS 0.26
Dataease < 2.10.10 - Authentication Bypass by Spoofing
DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
CWE-290
Jun 03, 2025
CVE-2025-13390
10.0
CRITICAL
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.37
Wpdirectorykit WP Directory Kit < 1.4.4 - Authentication Bypass
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.
CWE-303
Dec 03, 2025
CVE-2025-69411
7.5
HIGH
NUCLEI
EPSS 0.10
ionCube tester plus <=1.3 - Path Traversal
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger ionCube tester plus ioncube-tester-plus allows Path Traversal.This issue affects ionCube tester plus: from n/a through <= 1.3.
CWE-22
Mar 05, 2026
CVE-2025-59342
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.06
esm.sh <136 - Path Traversal
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying ../ sequences in X-Zone-Id causes files to be written to arbitrary directories. Version 136.1 contains a patch.
CWE-24
Sep 17, 2025
CVE-2025-4524
9.8
CRITICAL
2 PoCs
Analysis
NUCLEI
EPSS 0.03
Madara WordPress <2.2.2 - Local File Inclusion
The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
CWE-22
May 21, 2025
CVE-2025-14124
8.6
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.07
Team WordPress <5.0.11 - SQL Injection
The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Jan 05, 2026
CVE-2025-67303
7.5
HIGH
6 PoCs
Analysis
NUCLEI
EPSS 0.02
ComfyUI-Manager <3.38 - Info Disclosure
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface
CWE-420
Jan 05, 2026
CVE-2025-13652
6.5
MEDIUM
NUCLEI
EPSS 0.04
CBX Bookmark & Favorite <2.0.4 - SQL Injection
The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89
Jan 06, 2026
CVE-2025-5350
5.9
MEDIUM
NUCLEI
EPSS 0.00
Wso2 API Control Plane - SSRF
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepted user-supplied URLs without proper validation, leading to server-side request forgery (SSRF). Additionally, the retrieved content was directly reflected in the HTTP response, enabling reflected cross-site scripting (XSS) in the admin user's browser context.
By tricking an administrator into accessing a crafted link, an attacker could force the server to fetch malicious content and reflect it into the admin’s browser, leading to arbitrary JavaScript execution for UI manipulation or data exfiltration. While session cookies are protected with the HttpOnly flag, the XSS still poses a significant security risk.
Furthermore, SSRF can be used by a privileged user to query internal services, potentially aiding in internal network enumeration if the target endpoints are reachable from the affected product.
CWE-918
Oct 24, 2025
CVE-2025-32614
8.8
HIGH
NUCLEI
EPSS 0.02
EventON <2.3.2 - Code Injection
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON eventon-lite allows PHP Local File Inclusion.This issue affects EventON: from n/a through <= 2.4.
CWE-98
Apr 11, 2025
CVE-2025-2221
7.5
HIGH
NUCLEI
EPSS 0.21
Wpcom Member < 1.7.7 - SQL Injection
The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89
Mar 14, 2025
CVE-2025-14340
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.00
Payara Server <4.1.2.191.54 - XSS
Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an attacker to mislead the administrator to change the admin password via URL Payload.
CWE-79
Feb 18, 2026
CVE-2025-55150
8.6
HIGH
1 Writeup
NUCLEI
EPSS 0.07
Stirling-PDF <1.1.0 - SSRF
Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitization which can be bypassed and result in SSRF. This issue has been patched in version 1.1.0.
CWE-918
Aug 11, 2025