0.0

CVE-2025-30616 - WordPress Latest Custom Post Type Updates plugin <= 1.3.0 - Reflected Cross Site Scripting (XSS) vu…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Wood Latest Custom Post Type Updates latest-custom-post-type-updates allows Reflected XSS.This issue affects Latest Custom Post Type Updates: from n/a through <= 1.3.0.

📅 Published: April 3, 2025, 1:27 p.m. 🔄 Last Modified: April 1, 2026, 5:20 p.m.

0.0

CVE-2025-30611 - WordPress Wptobe-signinup plugin <= 1.1.2 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wptobe Wptobe-signinup wptobe-signinup allows Reflected XSS.This issue affects Wptobe-signinup: from n/a through <= 1.1.2.

📅 Published: April 3, 2025, 1:27 p.m. 🔄 Last Modified: April 1, 2026, 5:20 p.m.

0.0

CVE-2025-30596 - WordPress include-file plugin <= 1 - Arbitrary File Download Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tstafford include-file include-file allows Path Traversal.This issue affects include-file: from n/a through <= 1.

📅 Published: April 3, 2025, 1:27 p.m. 🔄 Last Modified: April 1, 2026, 5:20 p.m.

9.1

CVSS3.1

CVE-2025-2946 - Cross-Site Vulnerability(XSS) due to arbitrary HTML/JavaScript gets executed while query result ren…

pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.

📅 Published: April 3, 2025, 12:23 p.m. 🔄 Last Modified: April 23, 2025, 10:24 p.m.

9.9

CVSS3.1

CVE-2025-2945 - pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment

Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_tool/download, where the query_commited parameter and /cloud/deploy endpoint, where the high_availability parameter is u…

📅 Published: April 3, 2025, 12:23 p.m. 🔄 Last Modified: Feb. 26, 2026, 6:28 p.m.

6.4

CVSS3.1

CVE-2024-9416 - Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting…

The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions <= 5.0.36) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac…

📅 Published: April 3, 2025, 12:22 p.m. 🔄 Last Modified: Dec. 15, 2025, 3:39 p.m.

6.1

CVSS3.1

CVE-2025-2299 - LuckyWP Table of Contents <= 2.1.10 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.10. This is due to missing or incorrect nonce validation on the 'ajaxEdit' function. This makes it possible for unauthenticated attackers to inject arbitrary web …

📅 Published: April 3, 2025, 11:12 a.m. 🔄 Last Modified: May 15, 2025, 7:54 p.m.

0.0

CVE-2025-3190 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

📅 Published: April 3, 2025, 9:30 a.m. 🔄 Last Modified: April 3, 2025, 3:15 p.m.

7.5

CVSS3.1

CVE-2024-53868 - Apache Traffic Server: Malformed chunked message body allows request smuggling

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.

📅 Published: April 3, 2025, 8:59 a.m. 🔄 Last Modified: April 29, 2025, 8:42 p.m.

5.1

CVSS4.0

CVE-2025-3152 - caipeichao ThinkOX Search search.html cross site scripting

A vulnerability classified as problematic has been found in caipeichao ThinkOX 1.0. This affects an unknown part of the file /ThinkOX-master/index.php?s=/Weibo/Index/search.html of the component Search. The manipulation of the argument keywords leads to cross site scripting. It is possible to initi…

📅 Published: April 3, 2025, 8 a.m. 🔄 Last Modified: April 7, 2025, 2:18 p.m.
Total resulsts: 342251
Page 5345 of 34,226
« previous page » next page
Filters