6.5

CVSS3.1

CVE-2025-68868 - WordPress Wp Text Slider Widget plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Text Slider Widget wp-text-slider-widget allows Stored XSS.This issue affects Wp Text Slider Widget: from n/a through <= 1.0.

πŸ“… Published: Dec. 29, 2025, 4:12 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

7.5

CVSS3.1

CVE-2025-68870 - WordPress CookieHint WP plugin <= 1.0.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in reDim GmbH CookieHint WP cookiehint-wp allows PHP Local File Inclusion.This issue affects CookieHint WP: from n/a through <= 1.0.0.

πŸ“… Published: Dec. 29, 2025, 4:09 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

7.1

CVSS3.1

CVE-2025-68876 - WordPress Invelity SPS connect plugin <= 1.0.8 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INVELITY Invelity SPS connect invelity-sps-connect allows Reflected XSS.This issue affects Invelity SPS connect: from n/a through <= 1.0.8.

πŸ“… Published: Dec. 29, 2025, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

7.5

CVSS3.1

CVE-2025-68877 - WordPress CedCommerce Integration for Good Market plugin <= 1.0.6 - Local File Inclusion vulnerabil…

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce CedCommerce Integration for Good Market ced-good-market-integration allows PHP Local File Inclusion.This issue affects CedCommerce Integration for Good Market: from n…

πŸ“… Published: Dec. 29, 2025, 4:03 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

6.9

CVSS4.0

CVE-2025-15195 - code-projects Assessment Management add-module.php sql injection

A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file /admin/add-module.php. This manipulation of the argument linked[] causes sql injection. The attack can be initiated remotely. The exploit has been publicly dis…

πŸ“… Published: Dec. 29, 2025, 4:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:12 a.m.

6.9

CVSS4.0

CVE-2025-69211 - Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnerable if it uses `@nestjs/platform-fastify`; relies on `NestMiddleware` (via `MiddlewareConsumer`) for security checks (a…

πŸ“… Published: Dec. 29, 2025, 4:01 p.m. πŸ”„ Last Modified: Feb. 20, 2026, 4:58 p.m.

7.1

CVSS3.1

CVE-2025-68878 - WordPress Advanced Custom CSS plugin <= 1.1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prasadkirpekar Advanced Custom CSS advanced-custom-css allows Reflected XSS.This issue affects Advanced Custom CSS: from n/a through <= 1.1.0.

πŸ“… Published: Dec. 29, 2025, 4 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

7.1

CVSS3.1

CVE-2025-68879 - WordPress Content Grid Slider plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Content Grid Slider content-grid-slider allows Reflected XSS.This issue affects Content Grid Slider: from n/a through <= 1.5.

πŸ“… Published: Dec. 29, 2025, 3:58 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

4.9

CVSS3.1

CVE-2025-68893 - WordPress WordPress Image shrinker plugin <= 1.1.0 - Server Side Request Forgery (SSRF) vulnerabili…

Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Side Request Forgery.This issue affects WordPress Image shrinker: from n/a through <= 1.1.0.

πŸ“… Published: Dec. 29, 2025, 3:56 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

9.9

CVSS3.1

CVE-2025-68897 - WordPress IF AS Shortcode plugin <= 1.2 - Remote Code Execution (RCE) vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-shortcode allows Code Injection.This issue affects IF AS Shortcode: from n/a through <= 1.2.

πŸ“… Published: Dec. 29, 2025, 3:55 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.
Total resulsts: 347632
Page 2229 of 34,764
Β« previous page Β» next page
Filters