4.8

CVSS3.1

CVE-2025-46229 - WordPress Textmetrics plugin <= 3.6.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics webtexttool allows Stored XSS.This issue affects Textmetrics: from n/a through <= 3.6.2.

๐Ÿ“… Published: April 22, 2025, 9:53 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:23 p.m.

5.4

CVSS3.1

CVE-2025-46228 - WordPress Event post plugin <= 5.9.11 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows DOM-Based XSS.This issue affects Event post: from n/a through <= 5.9.11.

๐Ÿ“… Published: April 22, 2025, 9:53 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:23 p.m.

5.4

CVSS3.1

CVE-2025-46227 - WordPress Custom Related Posts plugin <= 1.7.4 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts custom-related-posts allows Stored XSS.This issue affects Custom Related Posts: from n/a through <= 1.7.4.

๐Ÿ“… Published: April 22, 2025, 9:53 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:23 p.m.

5.4

CVSS3.1

CVE-2025-46226 - WordPress MPL-Publisher plugin <= 2.18.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publisher mpl-publisher allows Stored XSS.This issue affects MPL-Publisher: from n/a through <= 2.18.0.

๐Ÿ“… Published: April 22, 2025, 9:53 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:23 p.m.

6.5

CVSS3.1

CVE-2025-46225 - WordPress Post in page for Elementor plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post in page for Elementor: from n/a through 1.0.1.

๐Ÿ“… Published: April 22, 2025, 9:53 a.m. ๐Ÿ”„ Last Modified: May 7, 2025, 7:26 p.m.

7

CVSS4.0

CVE-2025-3519 - Replace uploaded files knowing the file upload ID

An authorization bypassย inย Unblu Spark allows aย participant of a conversationย to replace an existing, uploaded file. Every uploaded file in Unblu gets assigned with a randomly generated Universally Unique ID (UUID). In case a participant of this or another conversation gets access to such a file Iโ€ฆ

๐Ÿ“… Published: April 22, 2025, 8:51 a.m. ๐Ÿ”„ Last Modified: April 23, 2025, 2:08 p.m.

5.3

CVSS4.0

CVE-2025-3518 - File upload functionality possible even when disabled

It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can be enabled or disabled for specific use cases through configuration. In case the functionality is disabled for at least one use case, the syโ€ฆ

๐Ÿ“… Published: April 22, 2025, 8:49 a.m. ๐Ÿ”„ Last Modified: June 23, 2025, 7:22 p.m.

0.0

CVE-2025-46218 -

Not used

๐Ÿ“… Published: April 22, 2025, 7:37 a.m. ๐Ÿ”„ Last Modified: April 23, 2025, 3:15 a.m.

0.0

CVE-2025-46220 -

Not used

๐Ÿ“… Published: April 22, 2025, 7:37 a.m. ๐Ÿ”„ Last Modified: April 23, 2025, 3:15 a.m.

0.0

CVE-2025-46221 -

Not used

๐Ÿ“… Published: April 22, 2025, 7:37 a.m. ๐Ÿ”„ Last Modified: April 23, 2025, 3:15 a.m.
Total resulsts: 343942
Page 5175 of 34,395
ยซ previous page ยป next page
Filters