Application Detections Published in August 2025

Hitesh Kadu

In August, Qualys Web Application Scanning released QIDs targeting vulnerabilities in several widely used software products and frameworks, including:

OAuth2-Proxy, Squid, WordPress, Hashicorp, SolarWinds, JetBrains, 1Panel, Microsoft, Mattermost, SimpleHelp, SuiteCRM, Apache, CrushFTP, Adobe, Ivanti, NVIDIA, Sitecore, Jenkins, GitLab, Cisco and JWT.

Details about the following QIDs can be found in our knowledge base. Please review reports of the scanned applications for these detections and, if any are identified, follow the steps provided in the knowledge base to ensure applications are protected against the reported vulnerabilities. Immediate resolution of these vulnerabilities as soon as they are detected should be a priority for all organizations. If not addressed, these vulnerabilities can pose security risks, such as breaches, unauthorized access, and various malicious activities.

List of QIDs Released

QIDTitle
520072OAuth2-Proxy Authentication Bypass Vulnerability (CVE-2025-54576)
520073Squid Buffer Overflow Vulnerability (CVE-2025-54574)
530327WordPress Madara Core Plugin: Arbitrary File Deletion Vulnerability (CVE-2025-7712)
530354Hashicorp Vault Code Execution Vulnerability (CVE-2025-6000)
530355SolarWinds Web Help Desk XML External Entity Injection (XXE) Vulnerability (CVE-2025-26400)
530356JetBrains YouTrack Improper iframe Configuration Vulnerability (CVE-2025-54527)
530357WordPress Hydra Booking Plugin: Privilege Escalation Vulnerability (CVE-2025-7689)
530358WordPress AI Engine Plugin: Arbitrary File Upload Vulnerability (CVE-2025-7847)
5303601Panel Remote Code Execution Vulnerability (CVE-2025-54424)
530361Hashicorp Vault Improper Certificate Validation Vulnerability (CVE-2025-6037)
530362Hashicorp Vault Improper Privilege Management (CVE-2025-5999)
530363Hashicorp Vault TOTP Secrets Engine Code Reuse (CVE-2025-6014)
530364WordPress WP Import Export Lite Plugin: Arbitrary File Upload Vulnerability (CVE-2025-5061)
530365WordPress WP Import Export Lite Plugin: Arbitrary File Upload Vulnerability (CVE-2025-6207)
530366Microsoft FrontPage Extensions Configuration Information Disclosure
530367Microsoft FrontPage Extensions service.cnf File Disclosure
530368Mattermost Authorization Bypass Vulnerability (CVE-2025-6226)
530369WordPress Service Finder Bookings Plugin: Privilege Escalation Vulnerability (CVE-2025-5947)
530370WordPress Service Finder SMS System Plugin: Privilege Escalation Vulnerability (CVE-2025-5954)
530371WordPress CleverReach-WP Plugin: SQL Injection Vulnerability (CVE-2025-7036)
530372SimpleHelp Untrusted Control Sphere Vulnerability (CVE-2025-36727)
530373SimpleHelp Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2025-36728)
530374WordPress Request a Quote Form Plugin: Remote Code Execution Vulnerability (CVE-2025-8420)
530375SuiteCRM PHP Object Injection Vulnerability (CVE-2025-54785)
530376SuiteCRM InboundEmail SQL Injection Vulnerability (CVE-2025-54788)
530377Apache Seata Insecure Deserialization Vulnerability (CVE-2025-53606)
530378CrushFTP Authentication Bypass Vulnerability (CVE-2025-54309)
530379Apache Jackrabbit XML External Entity (XXE) Injection Vulnerability (CVE-2025-53689)
530380Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability (CVE-2025-24854)
530381Microsoft SharePoint Server Remote Code Execution Vulnerabilities (CVE-2025-49703, CVE-2025-49704)
530382Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2025-49701)
530383Microsoft SharePoint Server Spoofing Vulnerability (CVE-2025-49706)
530385Adobe Magento CMS Detected
530386Adobe Magento Improper Access Control Vulnerability (CVE-2025-43586)
530387Ivanti Avalanche SQL Injection Vulnerability (CVE-2025-8296)
530388Ivanti Avalanche Remote Code Execution (RCE) Vulnerability (CVE-2025-8297)
530389Ivanti Connect Secure (ICS) Denial of Service (DoS) Vulnerabilities (CVE-2025-5456, CVE-2025-5462)
530390Adobe Magento Improper Authorization Vulnerability (CVE-2025-43585)
530391Adobe Magento Cross-Site Scripting Vulnerability (CVE-2025-47110)
530392Adobe Magento Improper Access Control Vulnerability (CVE-2025-27206)
530393Adobe Experience Manager Forms Code Execution Vulnerability (CVE-2025-54253)
530394Adobe Experience Manager Forms XML External Entity (XXE) Vulnerability (CVE-2025-54254)
530395Adobe Magento Incorrect Authorization Vulnerability (CVE-2025-49550)
530396Adobe Magento Incorrect Authorization Vulnerability (CVE-2025-49549)
530397WordPress Contact Form Entries Plugin: PHP Object Injection Vulnerability (CVE-2025-7384)
530398WordPress B Blocks Plugin: Privilege Escalation Vulnerability (CVE-2025-8059)
530400WordPress B Slider Plugin: Arbitrary Plugin Installation Vulnerability (CVE-2025-8418)
530401NVIDIA Triton Inference Server Remote Code Execution (RCE) Vulnerabilities
530402WordPress StoryChief Plugin: Arbitrary File Upload Vulnerability (CVE-2025-7441)
530403Apache Tomcat HTTP/2 Denial of Service (DoS) Vulnerability (CVE-2025-48989)
530404Sitecore Experience Platform (XP) Authentication Bypass Vulnerability (CVE-2025-34509)
530405Sitecore Experience Platform (XP) File Disclosure Vulnerability (CVE-2024-46938)
530406Sitecore Experience Platform (XP) Insecure Deserialization Vulnerability (CVE-2019-9874)
530407Sitecore Experience Platform (XP) Insecure Deserialization Vulnerability (CVE-2019-9875)
530408NVIDIA Triton Inference Server Information Disclosure Vulnerabilities (CVE-2025-23320, CVE-2025-23333, CVE-2025-23334)
530409NVIDIA Triton Inference Server Denial of Service (DoS) Vulnerability (CVE-2025-23321)
530410NVIDIA Triton Inference Server Denial of Service (DoS) Vulnerabilities (CVE-2025-23322, CVE-2025-23331)
530411Apache Zeppelin Cross-Site Scripting (XSS) Vulnerability (CVE-2024-41177)
530412Jenkins Credentials Binding Plugin Credentials Disclosure Vulnerability (CVE-2025-53650)
530413NVIDIA Triton Inference Server Denial of Service (DoS) Vulnerabilities
530414GitLab CE/EE Cross-site Scripting Vulnerability (CVE-2025-7739)
530415GitLab CE/EE Cross-site Scripting Vulnerability (CVE-2025-6186)
530416Jenkins HTML Publisher Plugin Information Disclosure Vulnerability (CVE-2025-53651)
530417Jenkins Git Parameter Plugin Code Injection Vulnerability (CVE-2025-53652)
530418WordPress Cloudflare Image Resizing Plugin: Remote Code Execution Vulnerability (CVE-2025-8723)
530419WordPress E-cab Taxi Booking Manager Plugin: Privilege Escalation Vulnerability (CVE-2025-8898)
530420Jenkins Aqua Security Scanner Plugin Unencrypted Token Storage Vulnerability (CVE-2025-53653)
530421Jenkins Applitools Eyes Plugin Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2025-53658)
530422WordPress WP Webhooks Plugin: Arbitrary File Copy Vulnerability (CVE-2025-8895)
530425Cisco Identity Services Engine Remote Code Execution Vulnerabilities (CVE-2025-20281)
530426Jenkins Testsigma Test Plan Run Plugin API Key Exposure Vulnerability (CVE-2025-53661)
530427Adobe Magento Remote Code Execution Vulnerability (CVE-2019-8144)
530430Jenkins Warrior Framework Plugin Unencrypted Password Storage Vulnerability (CVE-2025-53675)
530431Jenkins Kryptowire Plugin Unencrypted API Key Storage Vulnerability (CVE-2025-53672)
530432Jenkins IBM Cloud DevOps Plugin Unencrypted Token Storage Vulnerability (CVE-2025-53663)
580802Endpoint Accessible Without Authentication
580803JWT none algorithm supported
580804Use of Outdated or Unsupported API Version
580805Sensitive Data Exposure through debug endpoint
580806Unauthorized Creation of Privileged Account
580808CRLF Injection
580809Authentication Bypass via Empty Password
580810Authentication Bypass using SQL Injection
580812IP Address Injection via HTTP Headers
580813DELETE Method Detected
580814JSON Web Token Error Stack Trace Exposure
580815Missing CSRF Token Validation
580816Improper CSRF Token Validation

What’s Next

Leverage the QID list to guide your remediation efforts and strengthen your risk posture.

Looking for more context or remediation tips? Head to Qualys KnowledgeBase for detailed analysis, actionable guidance, and expert-backed support.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *