4.1

CVSS4.0

CVE-2025-49846 - wire-ios accidentally logs message contents

wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages that were visible in the view port have been logged to the iOS system logs in clear text. Wire application logs created and managed by the application itself were not affected, esp…

πŸ“… Published: July 3, 2025, 4:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2025-48939 - tarteaucitron.js vulnerable to DOM Clobbering via document.currentScript

tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element, it could clob…

πŸ“… Published: July 3, 2025, 4:26 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 1:56 p.m.

8.8

CVSS3.1

CVE-2025-6926 - Security Authentication Bypass in CentralAuth

Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

πŸ“… Published: July 3, 2025, 4:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS3.1

CVE-2025-53500 - Stored XSS in MassEditRegex

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects Mediawiki - MassEditRegex Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from…

πŸ“… Published: July 3, 2025, 4:17 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:26 p.m.

8.8

CVSS3.1

CVE-2025-53501 - Content Access Bypass in Scribunto

Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - Scribunto Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43…

πŸ“… Published: July 3, 2025, 4:15 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 2:17 p.m.

6.5

CVSS3.1

CVE-2025-53502 - HTML injection in FeaturedFeeds

Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - FeaturedFeeds Extension: 1.39.X, 1.42.X, 1.43.X.

πŸ“… Published: July 3, 2025, 4:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS3.1

CVE-2025-53489 - XSS in GoogleDocs4MW

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GoogleDocs4MW Extension: from 1.42.X before 1.42.7, from 1.43.X befo…

πŸ“… Published: July 3, 2025, 4:06 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 1:20 p.m.

5.6

CVSS3.1

CVE-2025-53490 - Multiple XSS in CampaignEvents

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: from 1.43.X before 1.43.2.

πŸ“… Published: July 3, 2025, 4:04 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 1:19 p.m.

7.2

CVSS3.1

CVE-2025-5961 - Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+)…

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attacker…

πŸ“… Published: July 3, 2025, 1:44 p.m. πŸ”„ Last Modified: April 20, 2026, 8:30 p.m.

8.8

CVSS3.1

CVE-2025-2932 - JKDEVKIT <= 1.9.4 - Authenticated (Subscriber+) Arbitrary File Deletion

The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' function in all versions up to, and including, 1.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delet…

πŸ“… Published: July 3, 2025, 12:23 p.m. πŸ”„ Last Modified: April 21, 2026, 8 p.m.
Total resulsts: 349182
Page 4801 of 34,919
Β« previous page Β» next page
Filters