Medium 6.4
2025-06-29< 5.25.25
EZ SQL Reports Shortcode Widget and DB Backup <= 5.25.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via SQLREPORT Shortcode
Minimum safe version
5.25.25
Update to 5.25.25 or later to address 7 fixable vulnerabilities
EZ SQL Reports Shortcode Widget and DB Backup <= 5.25.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via SQLREPORT Shortcode
CVE-2025-30788
CVE-2025-30787
EZ SQL Reports Shortcode Widget and DB Backup 4.11.13 - 5.25.08 - Cross-Site Request Forgery to Remote Code Execution
CVE-2025-26887
EZ SQL Reports <= 4.11.33 - Authenticated Arbitrary File Download
EZ SQL Reports <= 4.11.33 - Authenticated Arbitrary Code Execution