5.3

CVSS3.1

CVE-2025-11738 - Media Library Assistant <= 3.29 - Unauthenticated Limited File Read

The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can co…

πŸ“… Published: Oct. 18, 2025, 5:41 a.m. πŸ”„ Last Modified: April 8, 2026, 4:49 p.m.

6.9

CVSS4.0

CVE-2025-11937 - Stored XSS through a system message in SecurePoll

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - SecurePoll Extension allows Stored XSS.This issue affects Mediawiki - SecurePoll Extension: master.

πŸ“… Published: Oct. 18, 2025, 5:14 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62666 - DoS vector through the cirrusbuilddoc query API

Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch Extension allows HTTP DoS.This issue affects Mediawiki - CirrusSearch Extension: from master before 1.43.

πŸ“… Published: Oct. 18, 2025, 4:47 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62667 - Stored XSS through article extracts in GrowthExperiments

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Stored XSS.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.

πŸ“… Published: Oct. 18, 2025, 4:42 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62668 - Insufficient permission checks in action=growthsetmentor

Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Resource Leak Exposure.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.

πŸ“… Published: Oct. 18, 2025, 4:39 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62669 - UserInfoCard: activeLocalBlocksAllWikis does not do permissions checks

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects Mediawiki - CentralAuth Extension: from master before 1.39.

πŸ“… Published: Oct. 18, 2025, 4:34 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62670 - Stored XSS through a system message in FlexDiagrams

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - FlexDiagrams Extension allows Stored XSS.This issue affects Mediawiki - FlexDiagrams Extension: master.

πŸ“… Published: Oct. 18, 2025, 4:29 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.4

CVSS3.1

CVE-2025-11361 - Essential Blocks <= 5.7.1 - Authenticated (Author+) Server-Side Request Forgery

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-le…

πŸ“… Published: Oct. 18, 2025, 4:25 a.m. πŸ”„ Last Modified: April 8, 2026, 7:23 p.m.

6.9

CVSS4.0

CVE-2025-62671 - Stored XSS through wikitext in Cargo

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: master.

πŸ“… Published: Oct. 18, 2025, 4:24 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-62662 - Stored XSS through system messages in AdvancedSearch

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - AdvancedSearch Extension allows Stored XSS.This issue affects Mediawiki - AdvancedSearch Extension: from master before 1.39.

πŸ“… Published: Oct. 18, 2025, 4:19 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.
Total resulsts: 344055
Page 2863 of 34,406
Β« previous page Β» next page
Filters