7.6

CVSS3.1

CVE-2025-4123 - grafana: Cross-site Scripting (XSS) in Grafana via Custom Frontend Plugins and Open Redirect

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permission…

📅 Published: May 15, 2025, 3:49 a.m. 🔄 Last Modified: Aug. 15, 2025, 7:37 p.m.

6.4

CVSS3.1

CVE-2025-4591 - Weluka Lite <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Weluka Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'weluka-map' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta…

📅 Published: May 15, 2025, 3:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-4126 - EG-Series <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes in the shortcode_title function. This makes it possi…

📅 Published: May 15, 2025, 3:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-3917 - 百度站长SEO合集(支持百度/神马/Bing/头条推送) <= 2.0.6 - Unauthenticated Arbitrary File Upload

The 百度站长SEO合集(支持百度/神马/Bing/头条推送) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download_remote_image_to_media_library function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to upload arbitr…

📅 Published: May 15, 2025, 3:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-4589 - Bon Toolkit <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Bon Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt-map' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker…

📅 Published: May 15, 2025, 3:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-4579 - WP Content Security Plugin <= 2.3 - Unauthenticated Stored Cross-Site Scripting via CSP-Report Fiel…

The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and effective-directive parameters in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a…

📅 Published: May 15, 2025, 1:59 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2025-48024 -

In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.

📅 Published: May 15, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-48050 - DOMPurify: DOMPurify Path Traversal Vulnerability

In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory. NOTE: the Supplier disputes the significance of this report because the "Uncontrolled data used in path expression" occurs "in a development helper script whi…

📅 Published: May 15, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-48051 -

powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.

📅 Published: May 15, 2025, midnight 🔄 Last Modified: June 12, 2025, 1:08 p.m.

5.4

CVSS3.1

CVE-2025-48027 -

The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolution for pginaloginserver.

📅 Published: May 15, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344739
Page 4962 of 34,474
« previous page » next page
Filters