7.6

CVSS3.1

CVE-2025-25112 - WordPress Social Links plugin <= 1.2 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kareemsultan Social Links social-links allows Command Line Execution through SQL Injection.This issue affects Social Links: from n/a through <= 1.2.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

8.1

CVSS3.1

CVE-2025-25109 - WordPress Vehicle Manager plugin <= 3.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky WP Vehicle Manager js-vehicle-manager allows PHP Local File Inclusion.This issue affects WP Vehicle Manager: from n/a through <= 3.1.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-25108 - WordPress SW Plus Plugin <= 2.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shalomworld SW Plus shalom-world-media-gallery allows Reflected XSS.This issue affects SW Plus: from n/a through <= 2.1.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-25102 - WordPress Yahoo BOSS Plugin <= 0.7 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Harrison Yahoo BOSS yahoo-boss allows Reflected XSS.This issue affects Yahoo BOSS: from n/a through <= 0.7.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-25099 - WordPress Appointment Buddy Widget By Accrete plugin <= 1.2. - Reflected Cross-Site Scripting vulne…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accreteinfosolution Appointment Buddy Widget appointment-buddy-online-appointment-booking-by-accrete allows Cross-Site Scripting (XSS).This issue affects Appointment Buddy Widget: from n/a through …

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-25092 - WordPress All push notification for WP plugin <= 1.5.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP all-push-notification allows Reflected XSS.This issue affects All push notification for WP: from n/a through <= 1.5.3.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-25090 - WordPress Dreamstime Stock Photos plugin <= 4.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dreamstime Dreamstime Stock Photos dreamstime-stock-photos allows Reflected XSS.This issue affects Dreamstime Stock Photos: from n/a through <= 4.1.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-25089 - WordPress Image Rotator plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appten Image Rotator appten-image-rotator allows Reflected XSS.This issue affects Image Rotator: from n/a through <= 2.0.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-25087 - WordPress seekXL Snapr plugin <= 2.0.6 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim seekXL Snapr seekxl-snapr allows Reflected XSS.This issue affects seekXL Snapr: from n/a through <= 2.0.6.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

0.0

CVE-2025-25084 - WordPress UniTimetable plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antrouss UniTimetable unitimetable allows Stored XSS.This issue affects UniTimetable: from n/a through <= 1.1.

πŸ“… Published: March 3, 2025, 1:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6482 of 34,919
Β« previous page Β» next page
Filters