7.2

CVSS3.1

CVE-2025-2009 - Newsletters <= 4.9.9.7 - Unauthenticated Stored Cross-Site Scripting

The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logging functionality in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scriโ€ฆ

๐Ÿ“… Published: March 26, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:46 p.m.

5.4

CVSS3.1

CVE-2025-2167 - Event post <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcodes in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attโ€ฆ

๐Ÿ“… Published: March 26, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:45 p.m.

7.2

CVSS3.1

CVE-2025-2257 - Total Upkeep โ€“ WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticateโ€ฆ

The Total Upkeep โ€“ WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level setting in proc_open() witโ€ฆ

๐Ÿ“… Published: March 26, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:40 p.m.

5.5

CVSS3.1

CVE-2024-30155 - HCL SX is susceptible to cookie with Insecure, Improper, or Missing SameSite attribute vulnerability

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

๐Ÿ“… Published: March 26, 2025, 7:59 a.m. ๐Ÿ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2023-52972 -

Huawei PCs have a vulnerability that allows low-privilege users to bypass SDDL permission checks . Successful exploitation this vulnerability could lead to termination of some system processes.

๐Ÿ“… Published: March 26, 2025, 6:39 a.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:55 p.m.

8.8

CVSS3.1

CVE-2024-13146 - Booknetic < 4.1.5 - Staff Creation via CSRF

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

๐Ÿ“… Published: March 26, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 30, 2025, 5:36 p.m.

3.5

CVSS3.1

CVE-2024-12683 - Smart Maintenance Mode < 1.5.2 - Admin+ Stored XSS

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: March 26, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 6, 2025, 7:08 p.m.

4.8

CVSS3.1

CVE-2024-11847 - WP SVG Upload <= 1.0.0 - Author+ Stored XSS via SVG

The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

๐Ÿ“… Published: March 26, 2025, 6 a.m. ๐Ÿ”„ Last Modified: June 25, 2025, 8:43 p.m.

6.4

CVSS3.1

CVE-2025-1784 - Spectra โ€“ WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scrโ€ฆ

The Spectra โ€“ WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributorโ€ฆ

๐Ÿ“… Published: March 26, 2025, 5:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:11 p.m.

6.1

CVSS3.1

CVE-2025-1490 - Smart Maintenance Mode <= 1.5.2 - Reflected Cross-Site Scripting via setstatus Parameter

The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the โ€˜setstatusโ€™ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrโ€ฆ

๐Ÿ“… Published: March 26, 2025, 2:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:23 p.m.
Total resulsts: 343921
Page 5687 of 34,393
ยซ previous page ยป next page
Filters