7.1

CVSS3.1

CVE-2025-26746 - WordPress Advanced Custom Fields: Link Picker Field plugin <= 1.2.8 - Reflected Cross Site Scriptin…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in caalami Advanced Custom Fields: Link Picker Field acf-link-picker-field allows Reflected XSS.This issue affects Advanced Custom Fields: Link Picker Field: from n/a through <= 1.2.8.

πŸ“… Published: April 15, 2025, 9:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

6.5

CVSS3.1

CVE-2025-26740 - WordPress SpaBiz plugin <= 1.0.18 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware SpaBiz spabiz allows DOM-Based XSS.This issue affects SpaBiz: from n/a through <= 1.0.18.

πŸ“… Published: April 15, 2025, 9:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.5

CVSS3.1

CVE-2025-26730 - WordPress Macro Calculator with Admin Email Optin & Data plugin <= 1.0 - Multiple Vulnerabilities v…

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator with Admin Email Optin & Data. This issue affects Macro Calculator with Admin Email Optin & Data: from n/a through 1.0.

πŸ“… Published: April 15, 2025, 9:53 p.m. πŸ”„ Last Modified: April 28, 2026, 4:11 p.m.

6.5

CVSS3.1

CVE-2025-22269 - WordPress Real Testimonials plugin <= 3.1.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from n/a through <= 3.1.6.

πŸ“… Published: April 15, 2025, 9:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

6.5

CVSS3.1

CVE-2025-22268 - WordPress Uncanny Toolkit for LearnDash plugin <= 3.7.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny Toolkit for LearnDash: from n/a through <= 3.7.0.1.

πŸ“… Published: April 15, 2025, 9:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

7.1

CVSS3.1

CVE-2025-22263 - WordPress Global Gallery plugin <= 8.8.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Global Gallery allows Reflected XSS. This issue affects Global Gallery: from n/a through 8.8.0.

πŸ“… Published: April 15, 2025, 9:53 p.m. πŸ”„ Last Modified: April 28, 2026, 4:10 p.m.

6.9

CVSS4.0

CVE-2025-31147 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key

Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

πŸ“… Published: April 15, 2025, 9:50 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 6:12 p.m.

6.9

CVSS4.0

CVE-2025-31360 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key

Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.

πŸ“… Published: April 15, 2025, 9:48 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:11 p.m.

6.9

CVSS4.0

CVE-2025-30512 - Growatt Cloud portal External Control of System or Configuration Setting

Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).

πŸ“… Published: April 15, 2025, 9:45 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 6:12 p.m.

6.9

CVSS4.0

CVE-2025-27927 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key

An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.

πŸ“… Published: April 15, 2025, 9:43 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 6:12 p.m.
Total resulsts: 348441
Page 5728 of 34,845
Β« previous page Β» next page
Filters