6.4

CVSS3.1

CVE-2025-8780 - Livemesh SiteOrigin Widgets <= 3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero Header and Pricing Table widgets in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it …

📅 Published: Dec. 13, 2025, 8:21 a.m. 🔄 Last Modified: April 20, 2026, 9:30 p.m.

6.4

CVSS3.1

CVE-2025-9856 - Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticate…

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sg_popup' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping on user supp…

📅 Published: Dec. 13, 2025, 8:21 a.m. 🔄 Last Modified: April 20, 2026, 7 p.m.

6.4

CVSS3.1

CVE-2025-8687 - Enter Addons <= 2.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown and …

The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image Comparison widgets in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

📅 Published: Dec. 13, 2025, 8:21 a.m. 🔄 Last Modified: April 20, 2026, 7 p.m.

6.4

CVSS3.1

CVE-2025-8199 - MarqueeAddons <= 2.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial M…

The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee widget in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: Dec. 13, 2025, 8:21 a.m. 🔄 Last Modified: April 20, 2026, 9:30 p.m.

6.4

CVSS3.1

CVE-2025-8195 - JetWidgets For Elementor <= 1.0.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via I…

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison and Subscribe widgets in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p…

📅 Published: Dec. 13, 2025, 8:21 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

6.5

CVSS3.1

CVE-2025-0969 - Brizy – Page Builder <= 2.7.16 - Authenticated (Contributor+) Sensitive Information Exposure via ge…

The Brizy – Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.16 via the get_users() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including e…

📅 Published: Dec. 13, 2025, 8:21 a.m. 🔄 Last Modified: April 22, 2026, 2 p.m.

6.4

CVSS3.1

CVE-2025-7960 - King Addons for Elementor <= 51.1.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization and output escaping on user supplied …

📅 Published: Dec. 13, 2025, 8:21 a.m. 🔄 Last Modified: April 21, 2026, 1 a.m.

9.4

CVSS4.0

CVE-2025-36747 - Hardcoded FTP Credentials within the firmware

ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware …

📅 Published: Dec. 13, 2025, 8:16 a.m. 🔄 Last Modified: Jan. 14, 2026, 6:05 p.m.

9.4

CVSS4.0

CVE-2025-36752 - Undocumented backup Account and No Password Configuration Capability

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt …

📅 Published: Dec. 13, 2025, 8:16 a.m. 🔄 Last Modified: Jan. 14, 2026, 6:05 p.m.

9.3

CVSS4.0

CVE-2025-36754 - Authentication bypass on web interface

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbi…

📅 Published: Dec. 13, 2025, 8:16 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2620 of 34,919
« previous page » next page
Filters