6.1

CVSS3.0

CVE-2025-25054 -

Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while logged in to the affected product, an arbitrary script may be executed on the web browser of the user.

๐Ÿ“… Published: Feb. 19, 2025, 5:52 a.m. ๐Ÿ”„ Last Modified: Feb. 19, 2025, 2:53 p.m.

5.4

CVSS3.0

CVE-2025-22888 -

Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be executed on a logged-in user's web browser.

๐Ÿ“… Published: Feb. 19, 2025, 5:52 a.m. ๐Ÿ”„ Last Modified: Feb. 19, 2025, 2:54 p.m.

6.4

CVSS3.1

CVE-2024-13799 - User Private Files โ€“ File Upload & Download Manager with Secure File Sharing <= 2.1.3 - Authenticatโ€ฆ

The User Private Files โ€“ File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜new-fldr-nameโ€™ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it โ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, 5:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:48 p.m.

6.4

CVSS3.1

CVE-2025-1065 - Visualizer: Tables and Charts Manager for WordPress <= 3.11.8 - Authenticated (Contributor+) Storedโ€ฆ

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping on user supplied attributeโ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, 5:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:37 p.m.

6.1

CVSS3.1

CVE-2025-1441 - Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Siโ€ฆ

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes it possible for unauthenticated attackโ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, 4:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:59 p.m.

4.3

CVSS3.1

CVE-2025-22622 - Age Verification - Reflected cross-site scripting (XSS)

Age Verification for your checkout page. Verify your customer's identity 1.20.0 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/class-wc-integration-agechecker-integration.php.

๐Ÿ“… Published: Feb. 19, 2025, 3:51 a.m. ๐Ÿ”„ Last Modified: Feb. 19, 2025, 3:08 p.m.

6.4

CVSS3.1

CVE-2024-13443 - Easypromos Plugin <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated โ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, 3:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:03 p.m.

7.2

CVSS3.1

CVE-2024-11582 - Subscribe2 โ€“ Form, Email Subscribers & Newsletters <= 10.43 - Unauthenticated Stored Cross-Site Scrโ€ฆ

The Subscribe2 โ€“ Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers โ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, 3:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:46 p.m.

6.9

CVSS4.0

CVE-2025-1448 - Synway SMG Gateway Management Software 9-12ping.php command injection

A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This issue affects some unknown processing of the file 9-12ping.php. The manipulation of the argument retry leads to command injection. The attack may be initiated remotely. The exploiโ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, 1:31 a.m. ๐Ÿ”„ Last Modified: Feb. 19, 2025, 2:50 p.m.

5.3

CVSS4.0

CVE-2025-1447 - kasuganosoras Pigeon index.php server-side request forgery

A vulnerability was found in kasuganosoras Pigeon 1.0.177. It has been declared as critical. This vulnerability affects unknown code of the file /pigeon/imgproxy/index.php. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. Upgrading to โ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 19, 2025, 2:50 p.m.
Total resulsts: 343947
Page 6167 of 34,395
ยซ previous page ยป next page
Filters