6.9

CVSS4.0

CVE-2025-61987 -

GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.

πŸ“… Published: Dec. 12, 2025, 5:02 a.m. πŸ”„ Last Modified: Feb. 17, 2026, 3:31 p.m.

5.3

CVSS4.0

CVE-2025-61950 -

In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. With some crafted request, a logged-in user may alter the memo field. The affected products and versions are GroupSession Free edition prior to ver5.3.0, GroupS…

πŸ“… Published: Dec. 12, 2025, 5:02 a.m. πŸ”„ Last Modified: Feb. 17, 2026, 3:43 p.m.

5.1

CVSS4.0

CVE-2025-65120 -

Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.

πŸ“… Published: Dec. 12, 2025, 5:02 a.m. πŸ”„ Last Modified: Feb. 17, 2026, 3:09 p.m.

5.1

CVSS4.0

CVE-2025-57883 -

Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.

πŸ“… Published: Dec. 12, 2025, 5:01 a.m. πŸ”„ Last Modified: Jan. 23, 2026, 2:29 a.m.

4.8

CVSS4.0

CVE-2025-66284 -

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when an…

πŸ“… Published: Dec. 12, 2025, 5:01 a.m. πŸ”„ Last Modified: Feb. 17, 2026, 3:07 p.m.

4.8

CVSS4.0

CVE-2025-53523 -

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when an…

πŸ“… Published: Dec. 12, 2025, 5:01 a.m. πŸ”„ Last Modified: Feb. 17, 2026, 3:45 p.m.

5.1

CVSS4.0

CVE-2025-54407 -

Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.

πŸ“… Published: Dec. 12, 2025, 5:01 a.m. πŸ”„ Last Modified: Feb. 17, 2026, 3:44 p.m.

8.2

CVSS3.1

CVE-2025-66492 - Masa CMS vulnerable to Cross-Site Scripting (XSS) through URL Parameter

Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0-alpha.1 through 7.4.8 and 7.5.0 through 7.5.1 are vulnerable to XSS when an unsanitized value of the ajax URL query parameter is directly included within the <head> section of th…

πŸ“… Published: Dec. 12, 2025, 4:50 a.m. πŸ”„ Last Modified: Dec. 22, 2025, 6:46 p.m.

6.1

CVSS3.1

CVE-2025-14138 - WPLG Default Mail From <= 1.0.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The WPLG Default Mail From plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:34 p.m.

4.4

CVSS3.1

CVE-2025-13975 - Contact Form 7 with ChatWork <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting …

The Contact Form 7 with ChatWork plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_token' and 'roomid' settings in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi…

πŸ“… Published: Dec. 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:33 p.m.
Total resulsts: 343923
Page 2117 of 34,393
Β« previous page Β» next page
Filters