5.3

CVSS4.0

CVE-2025-15391 - D-Link DIR-806A SSDP Request ssdpcgi_main command injection

A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. This v…

πŸ“… Published: Dec. 31, 2025, 5:32 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:44 p.m.

5.9

CVSS3.1

CVE-2025-49355 - WordPress Accessibility Press plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ikaes Accessibility Press ilogic-accessibility allows Stored XSS.This issue affects Accessibility Press: from n/a through <= 1.0.2.

πŸ“… Published: Dec. 31, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

5.9

CVSS3.1

CVE-2025-49337 - WordPress Dashboard Beacon plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashboard Beacon wp-dashboard-beacon allows Stored XSS.This issue affects Dashboard Beacon: from n/a through <= 1.2.0.

πŸ“… Published: Dec. 31, 2025, 5:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

5.9

CVSS3.1

CVE-2025-59135 - WordPress Behance Portfolio Manager plugin <= 1.7.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Stored XSS.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5.

πŸ“… Published: Dec. 31, 2025, 5:20 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.9

CVSS3.1

CVE-2025-62989 - WordPress Cooked plugin <= 1.11.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gora Tech Cooked cooked allows Stored XSS.This issue affects Cooked: from n/a through <= 1.11.3.

πŸ“… Published: Dec. 31, 2025, 5:19 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

7.1

CVSS3.1

CVE-2025-23608 - WordPress LIVE TV plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omar Mohamed Mohamoud LIVE TV live-tv allows Reflected XSS.This issue affects LIVE TV: from n/a through <= 1.2.

πŸ“… Published: Dec. 31, 2025, 5:07 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

5.4

CVSS3.1

CVE-2025-62088 - WordPress WordPress & WooCommerce Scraper plugin, Import Data from Any Site plugin <= 1.0.7 - Serve…

Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: from n/a through <= 1.0.7.

πŸ“… Published: Dec. 31, 2025, 5:04 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

4.9

CVSS3.1

CVE-2025-59138 - WordPress Genemy theme <= 1.6.6 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in Jthemes Genemy genemy allows Server Side Request Forgery.This issue affects Genemy: from n/a through <= 1.6.6.

πŸ“… Published: Dec. 31, 2025, 5:03 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.1

CVSS4.0

CVE-2019-25262 - elinicksic Razgover Chat Message send.php cross site scripting

A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This affects an unknown part of the file Chattify/send.php of the component Chat Message Handler. Such manipulation of the argument msg leads to cross site scripting. The attack may be …

πŸ“… Published: Dec. 31, 2025, 5:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-66154 - WordPress Couponer for Elementor plugin <= 1.1.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in merkulove Couponer for Elementor couponer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Couponer for Elementor: from n/a through <= 1.1.7.

πŸ“… Published: Dec. 31, 2025, 5:01 p.m. πŸ”„ Last Modified: April 23, 2026, 3:35 p.m.
Total resulsts: 347617
Page 2164 of 34,762
Β« previous page Β» next page
Filters