6.5

CVSS3.1

CVE-2025-31094 - WordPress WP Posts Carousel plugin <= 1.3.8 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Stored XSS.This issue affects WP Posts Carousel: from n/a through <= 1.3.8.

πŸ“… Published: March 28, 2025, 9:39 a.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

6.5

CVSS3.1

CVE-2025-31096 - WordPress PostX plugin <= 4.1.25 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultimate-post allows DOM-Based XSS.This issue affects PostX: from n/a through <= 4.1.25.

πŸ“… Published: March 28, 2025, 9:39 a.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

7.6

CVSS3.1

CVE-2025-31099 - WordPress Slider by BestWebSoft plugin <= 1.1.0 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bestweblayout Slider by BestWebSoft slider-bws allows SQL Injection.This issue affects Slider by BestWebSoft: from n/a through <= 1.1.0.

πŸ“… Published: March 28, 2025, 9:39 a.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

7.1

CVSS3.1

CVE-2025-31102 - WordPress Hostel plugin <= 1.1.5.5 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5.5.

πŸ“… Published: March 28, 2025, 9:39 a.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

6.5

CVSS3.1

CVE-2025-27001 - WordPress Shipmondo – A complete shipping solution for WooCommerce plugin <= 5.0.3 - Authenticated …

Insertion of Sensitive Information Into Sent Data vulnerability in Shipmondo Shipmondo – A complete shipping solution for WooCommerce pakkelabels-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Shipmondo – A complete shipping solution for WooCommerce: from n/a through <= …

πŸ“… Published: March 28, 2025, 9:38 a.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

5.4

CVSS3.1

CVE-2019-16149 -

An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.

πŸ“… Published: March 28, 2025, 9:07 a.m. πŸ”„ Last Modified: July 15, 2025, 6:59 p.m.

6.1

CVSS3.1

CVE-2025-1705 - tagDiv Composer <= 5.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation within the td_ajax_get_views AJAX action. This makes it possible for unauthenticated attackers to inject malicious web…

πŸ“… Published: March 28, 2025, 8:23 a.m. πŸ”„ Last Modified: April 22, 2026, 5:45 p.m.

8.1

CVSS3.0

CVE-2025-27932 -

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an attacker may delete a file on the device or cause a d…

πŸ“… Published: March 28, 2025, 8:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.1

CVSS3.0

CVE-2025-27726 -

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered by a …

πŸ“… Published: March 28, 2025, 8:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.0

CVE-2025-27718 -

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered or arbi…

πŸ“… Published: March 28, 2025, 8:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6153 of 34,919
Β« previous page Β» next page
Filters