5.4

CVSS3.1

CVE-2025-13196 - Element Pack Addons for Elementor <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scriptiโ€ฆ

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in all versions up to, and including, 8.3.4. This is due to insufficient input sanitization and output escaping on user-supplied attributโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 9:27 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-4212 - Checkout Files Upload for WooCommerce <= 2.2.1 - Unauthenticated Stored Cross-Site Scripting

The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitraโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 9:27 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-11734 - Broken Link Checker by AIOSEO โ€“ Easily Fix/Monitor Internal and External links <= 1.2.5 - Missing Aโ€ฆ

The Broken Link Checker by AIOSEO โ€“ Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization in all versions up to, and including, 1.2.5. This is due to the plugin registering a REST API endpoint that only checkโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 9:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:15 p.m.

4.8

CVSS3.1

CVE-2025-40545 - SolarWinds Observability Self-Hosted Open Redirection Vulnerability

SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.

๐Ÿ“… Published: Nov. 18, 2025, 8:55 a.m. ๐Ÿ”„ Last Modified: Nov. 24, 2025, 4:30 p.m.

5.4

CVSS3.1

CVE-2025-26391 - SolarWinds Observability Self-Hosted XSS Vulnerability

SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.

๐Ÿ“… Published: Nov. 18, 2025, 8:53 a.m. ๐Ÿ”„ Last Modified: Nov. 24, 2025, 4:31 p.m.

9.1

CVSS3.1

CVE-2025-40549 - SolarWinds Serv-U Path Restriction Bypass Vulnerability

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences โ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 8:41 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:56 p.m.

9.1

CVSS3.1

CVE-2025-40548 - SolarWinds Serv-U Broken Access Control - Remote Code Execution Vulnerability

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run underโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:56 p.m.

9.1

CVSS3.1

CVE-2025-40547 - SolarWinds Serv-U Logic Abuse - Remote Code Execution Vulnerability

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run uโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 8:35 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:56 p.m.

6.4

CVSS3.1

CVE-2025-11868 - everviz <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The everviz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `everviz` shortcode attributes in versions up to, and including, 1.1. This is due to the plugin not properly sanitizing user input or escaping output when building a `<div id=...>` from the `type` and `hash` attriโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 8:27 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:45 a.m.

6.1

CVSS3.1

CVE-2025-12078 - ArtiBot Free Chat Bot for WebSites <= 1.1.7 - Reflected Cross-Site Scripting via PostMessage

The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrarโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 8:27 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:45 a.m.
Total resulsts: 349182
Page 2979 of 34,919
ยซ previous page ยป next page
Filters