7.1

CVSS3.1

CVE-2025-23624 - WordPress WpDevTool plugin <= 0.1.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alessandro Benoit WpDevTool wpdevtool allows Reflected XSS.This issue affects WpDevTool: from n/a through <= 0.1.1.

πŸ“… Published: Jan. 23, 2025, 3:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

7.1

CVSS3.1

CVE-2025-23545 - WordPress WP Social Broadcast plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Navnish Bhardwaj WP Social Broadcast wp-social-broadcast allows Reflected XSS.This issue affects WP Social Broadcast: from n/a through <= 1.0.0.

πŸ“… Published: Jan. 23, 2025, 3:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-23544 - WordPress StatPressCN plugin <= 1.9.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in heart5 StatPressCN statpresscn allows Reflected XSS.This issue affects StatPressCN: from n/a through <= 1.9.1.

πŸ“… Published: Jan. 23, 2025, 3:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-23541 - WordPress Download, Downloads plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in edmon.parker Download, Downloads ydn-download allows Reflected XSS.This issue affects Download, Downloads : from n/a through <= 1.4.2.

πŸ“… Published: Jan. 23, 2025, 3:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-22768 - WordPress Rocket Media Library Mime Type plugin <= 2.1.0 - CSRF to Stored Cross Site Scripting (XSS…

Cross-Site Request Forgery (CSRF) vulnerability in JinHan Park Rocket Media Library Mime Type rocket-media-library-mime-type allows Stored XSS.This issue affects Rocket Media Library Mime Type: from n/a through <= 2.1.0.

πŸ“… Published: Jan. 23, 2025, 3:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-22264 - WordPress WP Query Creator plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Patel WP Query Creator wp-query-creator allows Reflected XSS.This issue affects WP Query Creator: from n/a through <= 1.0.

πŸ“… Published: Jan. 23, 2025, 3:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

9.8

CVSS3.1

CVE-2025-0637 - Inadequate access control in Beta10

It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to access private areas and/or areas intended for other roles. The vulnerability has been identif…

πŸ“… Published: Jan. 23, 2025, 3:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-10846 - Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recurs…

The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from versions v2.27.0 to v2.29.7 included

πŸ“… Published: Jan. 23, 2025, 3:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-23540 - WordPress WP Front-end login and register plugin <= 2.1.0 - Reflected Cross Site Scripting (XSS) vu…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohsin Khan WP Front-end login and register wp-front-end-login-and-register allows Reflected XSS.This issue affects WP Front-end login and register: from n/a through <= 2.1.0.

πŸ“… Published: Jan. 23, 2025, 3:20 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

5.5

CVSS3.1

CVE-2024-10539 - Reflected XSS in Uyumsoft's ERP

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft Informatin Systems Uyumsoft ERP allows XSS Using Invalid Characters, Reflected XSS.This issue affects Uyumsoft ERP: before Erp4.2109.166p45.

πŸ“… Published: Jan. 23, 2025, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6988 of 34,919
Β« previous page Β» next page
Filters