6.4

CVSS3.1

CVE-2025-11818 - WP Responsive Meet The Team <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The WP Responsive Meet The Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wprm_team' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut…

πŸ“… Published: Oct. 22, 2025, 8:27 a.m. πŸ”„ Last Modified: April 8, 2026, 4:44 p.m.

6.4

CVSS3.1

CVE-2025-11807 - Mixlr Shortcode <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Mixlr Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mixlr' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on the 'url' attribute. This makes it possible for authenticated attackers,…

πŸ“… Published: Oct. 22, 2025, 8:27 a.m. πŸ”„ Last Modified: April 8, 2026, 4:42 p.m.

6.4

CVSS3.1

CVE-2025-10138 - This-or-That by AndrΓ© Boekhorst <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The This-or-That plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'thisorthat' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

πŸ“… Published: Oct. 22, 2025, 8:27 a.m. πŸ”„ Last Modified: April 8, 2026, 4:41 p.m.

6.4

CVSS3.1

CVE-2025-11827 - Oboxmedia Ads <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Oboxmedia Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_widget' and 'after_widget' parameters of the oboxads-ad-widget shortcode in all versions up to, and including, 1.9.8. This is due to insufficient input sanitization and output escaping. This makes it…

πŸ“… Published: Oct. 22, 2025, 8:27 a.m. πŸ”„ Last Modified: April 8, 2026, 4:40 p.m.

6.4

CVSS3.1

CVE-2025-11878 - ST Categories Widget <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The ST Categories Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's st-categories shortcode in versions less than, or equal to, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

πŸ“… Published: Oct. 22, 2025, 8:27 a.m. πŸ”„ Last Modified: April 8, 2026, 4:35 p.m.

6.4

CVSS3.1

CVE-2025-11809 - WP-Force Images Download <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shor…

The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode in all versions up to, and including, 1.8. This is due to insufficient input sanitization and output escaping on the 'class' attribute. This makes it possible for authenticated a…

πŸ“… Published: Oct. 22, 2025, 8:27 a.m. πŸ”„ Last Modified: April 8, 2026, 5:20 p.m.

6.4

CVSS3.1

CVE-2025-11872 - Material Design Iconic Font Integration <= 2 - Authenticated (Contributor+) Stored Cross-Site Scrip…

The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdiconic' shortcode in all versions up to, and including, 2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

πŸ“… Published: Oct. 22, 2025, 8:27 a.m. πŸ”„ Last Modified: April 8, 2026, 4:33 p.m.

6.4

CVSS3.1

CVE-2025-11804 - JB News Ticker <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The JB News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the 'jbticker' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated a…

πŸ“… Published: Oct. 22, 2025, 8:27 a.m. πŸ”„ Last Modified: April 8, 2026, 4:33 p.m.

6.4

CVSS3.1

CVE-2025-11834 - WP AD Gallery <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP AD Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'startindex' parameter of the ad-gallery shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta…

πŸ“… Published: Oct. 22, 2025, 8:27 a.m. πŸ”„ Last Modified: April 8, 2026, 4:32 p.m.

5.3

CVSS4.0

CVE-2025-11952 - Stored Cross-Site Scripting (XSS) in Oct8ne Chatbot

Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user…

πŸ“… Published: Oct. 22, 2025, 8:22 a.m. πŸ”„ Last Modified: Oct. 31, 2025, 2:47 p.m.
Total resulsts: 343749
Page 2794 of 34,375
Β« previous page Β» next page
Filters