6.4

CVSS4.0

CVE-2025-30362 - WeGIA vulnerable to Stored XSS in documentos_funcionario.php parameter id

WeGIA is a Web manager for charitable institutions. A stored Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 3.2.8. This vulnerability allows unauthorized scripts to be executed within the user's browser context. Stored XSS is particularly critical, as the malicious cod…

πŸ“… Published: March 27, 2025, 4:23 p.m. πŸ”„ Last Modified: April 10, 2025, 3:14 p.m.

9.3

CVSS4.0

CVE-2025-30361 - WeGIA Vulnerable to Broken Authentication - Old Password Validation

WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to change a user's password without verifying the old password. This issue exists in the control.php endpoint and allows unauthorized attackers to bypass auth…

πŸ“… Published: March 27, 2025, 4:22 p.m. πŸ”„ Last Modified: April 10, 2025, 3:16 p.m.

8.8

CVSS3.1

CVE-2025-22783 - WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo allows SQL Injection.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.03.

πŸ“… Published: March 27, 2025, 3:56 p.m. πŸ”„ Last Modified: April 1, 2026, 4:23 p.m.

0.0

CVE-2025-26762 - WordPress WooCommerce plugin <= 9.7.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through <= 9.7.0.

πŸ“… Published: March 27, 2025, 3:52 p.m. πŸ”„ Last Modified: April 1, 2026, 5:18 p.m.

9.8

CVSS3.1

CVE-2025-26909 - WordPress Hide My WP Ghost plugin <= 5.4.01 - Local File Inclusion to RCE vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through <= 5.4.01.

πŸ“… Published: March 27, 2025, 3:48 p.m. πŸ”„ Last Modified: April 1, 2026, 5:19 p.m.

6.5

CVSS3.1

CVE-2025-22278 - WordPress Whitish Lite theme <= 2.1.13 - Stored Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes Whitish Lite allows Stored XSS.This issue affects Whitish Lite: from n/a through 2.1.13.

πŸ“… Published: March 27, 2025, 3:33 p.m. πŸ”„ Last Modified: July 12, 2025, 10:31 p.m.

0.0

CVE-2025-22496 - WordPress Notif Bell Plugin <= 0.9.8 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MarMar8x Notif Bell notif-bell allows Stored XSS.This issue affects Notif Bell: from n/a through <= 0.9.8.

πŸ“… Published: March 27, 2025, 3:32 p.m. πŸ”„ Last Modified: April 1, 2026, 4:22 p.m.

0.0

CVE-2025-22497 - WordPress Simple Google Calendar Outlook Events Block Widget plugin <= 2.5.0 - Cross Site Scripting…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bramwaas Simple Google Calendar Outlook Events Block Widget simple-google-icalendar-widget allows Stored XSS.This issue affects Simple Google Calendar Outlook Events Block Widget: from n/a through …

πŸ“… Published: March 27, 2025, 3:31 p.m. πŸ”„ Last Modified: April 1, 2026, 4:22 p.m.

5.1

CVSS4.0

CVE-2025-2855 - elunez eladmin upload checkFile deserialization

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. The manipulation of the argument servers leads to deserialization. The attack may be launched remotely.

πŸ“… Published: March 27, 2025, 3:31 p.m. πŸ”„ Last Modified: May 6, 2025, 7:07 p.m.

0.0

CVE-2025-22628 - WordPress Filled In Plugin <= 1.9.2 - CSRF to Stored XSS vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision Filled In filled-in allows Stored XSS.This issue affects Filled In: from n/a through <= 1.9.2.

πŸ“… Published: March 27, 2025, 3:30 p.m. πŸ”„ Last Modified: April 1, 2026, 4:22 p.m.
Total resulsts: 343060
Page 5550 of 34,306
Β« previous page Β» next page
Filters