6.9

CVSS4.0

CVE-2025-62669 - UserInfoCard: activeLocalBlocksAllWikis does not do permissions checks

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects Mediawiki - CentralAuth Extension: from master before 1.39.

πŸ“… Published: Oct. 18, 2025, 4:34 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62670 - Stored XSS through a system message in FlexDiagrams

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - FlexDiagrams Extension allows Stored XSS.This issue affects Mediawiki - FlexDiagrams Extension: master.

πŸ“… Published: Oct. 18, 2025, 4:29 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.4

CVSS3.1

CVE-2025-11361 - Essential Blocks <= 5.7.1 - Authenticated (Author+) Server-Side Request Forgery

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-le…

πŸ“… Published: Oct. 18, 2025, 4:25 a.m. πŸ”„ Last Modified: April 8, 2026, 7:23 p.m.

6.9

CVSS4.0

CVE-2025-62671 - Stored XSS through wikitext in Cargo

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: master.

πŸ“… Published: Oct. 18, 2025, 4:24 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62662 - Stored XSS through system messages in AdvancedSearch

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - AdvancedSearch Extension allows Stored XSS.This issue affects Mediawiki - AdvancedSearch Extension: from master before 1.39.

πŸ“… Published: Oct. 18, 2025, 4:19 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62663 - Stored XSS through a system message in UploadWizard

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - UploadWizard Extension allows Stored XSS.This issue affects Mediawiki - UploadWizard Extension: from master before 1.39.

πŸ“… Published: Oct. 18, 2025, 4:16 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62664 - Stored XSS through a system message in ImageRating

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - ImageRating Extension allows Stored XSS.This issue affects Mediawiki - ImageRating Extension: from master before 1.39.

πŸ“… Published: Oct. 18, 2025, 4:13 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62665 - Stored XSS through system messages in Skin:BlueSky

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Skin:BlueSky allows Stored XSS.This issue affects Mediawiki - Skin:BlueSky: from master before 1.39.

πŸ“… Published: Oct. 18, 2025, 4:10 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

9.8

CVSS3.1

CVE-2017-20208 - RegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible fo…

πŸ“… Published: Oct. 18, 2025, 3:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:20 p.m.

9.8

CVSS3.1

CVE-2017-20207 - Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection

The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerabili…

πŸ“… Published: Oct. 18, 2025, 3:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:17 p.m.
Total resulsts: 343970
Page 2855 of 34,397
Β« previous page Β» next page
Filters