Critical Alert 3 Active Exploits Detected Today

CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability →
CVE-2026-45321 TanStack Unspecified Vulnerability →
CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

← Back to CVE List

CVE-2025-9501NVD

Description

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.
Severity Level
UNKNOWN
Published Date
17/11/2025
Last Modified
17/11/2025
Exploitation Status
UNKNOWN