Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-11-06

CVE-2025-10567 - Funnelkit Plugin

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.

PLUGIN Funnelkit

CVE-2025-10567

MEDIUM CVSS 6.3 2025-11-05
Threat Entry Updated 2025-06-12

CVE-2025-2203 - Funnelkit Plugin

The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

PLUGIN Funnelkit

CVE-2025-2203

MEDIUM CVSS 6.1 2025-05-15
Scroll to top