5.3

CVSS4.0

CVE-2025-10011 - Portabilis i-Educar edit sql injection

A weakness has been identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /module/TabelaArredondamento/edit. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available …

πŸ“… Published: Sept. 5, 2025, 2:02 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 12:45 p.m.

6.5

CVSS3.1

CVE-2025-58887 - WordPress Course Booking Platform Plugin <= 1.0.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | andrΓ© martin - it solutions & research UG Course Booking Platform course-booking-platform allows Stored XSS.This issue affects Course Booking Platform: from n/a through <= 1.0.0.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

5.9

CVSS3.1

CVE-2025-58886 - WordPress Instant Locations Plugin <= 1.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tan Nguyen Instant Locations instant-locations allows Stored XSS.This issue affects Instant Locations: from n/a through <= 1.0.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.9

CVSS3.1

CVE-2025-58884 - WordPress vipdrv Plugin <= 1.0.3 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ivan Drago vipdrv vipdrv-vip-test-drive allows Stored XSS.This issue affects vipdrv: from n/a through <= 1.0.3.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.9

CVSS3.1

CVE-2025-58883 - WordPress Search Cloud One Plugin <= 2.2.5 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Search Cloud One search-cloud-one allows Stored XSS.This issue affects Search Cloud One: from n/a through <= 2.2.5.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-58882 - WordPress Simple Text Slider Plugin <= 1.0.5 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Text Slider simple-text-slider allows Stored XSS.This issue affects Simple Text Slider: from n/a through <= 1.0.5.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

8.5

CVSS3.1

CVE-2025-58881 - WordPress New Simple Gallery Plugin <= 8.0 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery new-simple-gallery allows Blind SQL Injection.This issue affects New Simple Gallery: from n/a through <= 8.0.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-58880 - WordPress Translate This gTranslate Shortcode Plugin <= 1.0 - Cross Site Scripting (XSS) Vulnerabil…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reubenthiessen Translate This gTranslate Shortcode translate-this-google-translate-web-element-shortcode allows Stored XSS.This issue affects Translate This gTranslate Shortcode: from n/a through <…

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-58878 - WordPress Woocommerce Gifts Product Plugin <= 1.0.0 - Cross Site Request Forgery (CSRF) Vulnerabili…

Cross-Site Request Forgery (CSRF) vulnerability in usamafarooq Woocommerce Gifts Product woo-gift-product allows Cross Site Request Forgery.This issue affects Woocommerce Gifts Product: from n/a through <= 1.0.0.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-58876 - WordPress Aparat Video Shortcode Plugin <= 0.2.4 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Aghdam Aparat Video Shortcode aparat-shortcode allows Stored XSS.This issue affects Aparat Video Shortcode: from n/a through <= 0.2.4.

πŸ“… Published: Sept. 5, 2025, 1:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.
Total resulsts: 349182
Page 3981 of 34,919
Β« previous page Β» next page
Filters