4.3

CVSS3.1

CVE-2025-22787 - WordPress Button Block plugin <= 1.1.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through <= 1.1.5.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

5.9

CVSS3.1

CVE-2025-22788 - WordPress CoDesigner plugin <= 4.29 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codexpert, Inc CoDesigner woolementor allows Stored XSS.This issue affects CoDesigner: from n/a through <= 4.29.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

0.0

CVE-2025-22793 - WordPress Bold pagos en linea Plugin <= 3.1.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bold Bold pagos en linea bold-pagos-en-linea allows DOM-Based XSS.This issue affects Bold pagos en linea: from n/a through <= 3.1.4.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-22795 - WordPress Multilang Contact Form Plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows Reflected XSS.This issue affects Multilang Contact Form: from n/a through <= 1.5.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

6.5

CVSS3.1

CVE-2025-22797 - WordPress Gallery and Lightbox plugin <= 1.0.14 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oğulcan Γ–zΓΌgenΓ§ Gallery and Lightbox gallery-and-lightbox allows Stored XSS.This issue affects Gallery and Lightbox: from n/a through <= 1.0.14.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

6.5

CVSS3.1

CVE-2025-22798 - WordPress Responsive jQuery Slider plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CHR Designer Responsive jQuery Slider responsive-jquery-slider allows Stored XSS.This issue affects Responsive jQuery Slider: from n/a through <= 1.1.1.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

8.5

CVSS3.1

CVE-2025-22799 - WordPress Neon Product Designer Plugin <= 2.2.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-woocommerce allows SQL Injection.This issue affects Neon Product Designer: from n/a through <= 2.2.0.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

8.7

CVSS3.1

CVE-2024-47140 -

A cross-site scripting (xss) vulnerability exists in the add_alert_check page of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript code execution. An authenticated user would need to click a malicious link provided by the attacker.

πŸ“… Published: Jan. 15, 2025, 2:59 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:19 p.m.

8.7

CVSS3.1

CVE-2024-47002 -

A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker.

πŸ“… Published: Jan. 15, 2025, 2:59 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:22 p.m.

8.7

CVSS3.1

CVE-2024-45061 -

A cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript code execution. An authenticated user would need to click a malicious link provided by the attacker.

πŸ“… Published: Jan. 15, 2025, 2:59 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:25 p.m.
Total resulsts: 347969
Page 6982 of 34,797
Β« previous page Β» next page
Filters