The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks.
Cyber News related to CVE-2025-14973
CVE-2025-14973 - The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks. ...
56 years ago
CVE-2017-14973 - IDenticard Two-Reader Controller Configuration Manager 1.18.8 (396) is vulnerable to Stored Cross-Site Scripting (XSS) via the notes field in /~user_handler?filelogged_in.shtm (aka the edit user page). ...
8 years ago
CVE-2018-14973 - An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS. ...
7 years ago
CVE-2020-14973 - The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string. ...
5 years ago
CVE-2019-14973 - _TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application ...
2 years ago