4.8

CVSS4.0

CVE-2025-2617 - yangyouwang 杨有旺 crud 简约后台管理系统 Department Page cross site scripting

A vulnerability classified as problematic was found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected by this vulnerability is an unknown functionality of the component Department Page. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclose…

📅 Published: March 22, 2025, 12:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-26796 - Apache Oozie: XSS in Oozie Web Console

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recom…

📅 Published: March 22, 2025, 12:23 p.m. 🔄 Last Modified: April 1, 2025, 8:27 p.m.

4.9

CVSS3.1

CVE-2025-1973 - Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrato…

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitra…

📅 Published: March 22, 2025, 11:23 a.m. 🔄 Last Modified: April 22, 2026, 5:45 p.m.

5.3

CVSS3.1

CVE-2025-2331 - GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive…

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 via a misconfigured capability check in the 'permissionsCheck' function. This makes it possible for authenticated attackers, with S…

📅 Published: March 22, 2025, 11:18 a.m. 🔄 Last Modified: April 21, 2026, 10 p.m.

7.6

CVSS3.1

CVE-2025-1970 - Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request…

The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web reques…

📅 Published: March 22, 2025, 11:18 a.m. 🔄 Last Modified: April 21, 2026, 10 p.m.

7.2

CVSS3.1

CVE-2025-1971 - Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via fo…

The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access…

📅 Published: March 22, 2025, 11:18 a.m. 🔄 Last Modified: April 21, 2026, 10 p.m.

2.7

CVSS3.1

CVE-2025-1972 - Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrato…

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with Administrator-level…

📅 Published: March 22, 2025, 11:18 a.m. 🔄 Last Modified: April 22, 2026, 5:45 p.m.

6.4

CVSS3.1

CVE-2025-2577 - Bitspecter Suite <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Bitspecter Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above,…

📅 Published: March 22, 2025, 11:18 a.m. 🔄 Last Modified: April 22, 2026, 5:45 p.m.

4.8

CVSS4.0

CVE-2025-2616 - yangyouwang 杨有旺 crud 简约后台管理系统 Role Management Page cross site scripting

A vulnerability classified as problematic has been found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected is an unknown function of the component Role Management Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the…

📅 Published: March 22, 2025, 10 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-13666 - Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - …

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for I…

📅 Published: March 22, 2025, 8:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6252 of 34,919
« previous page » next page
Filters