7.1

CVSS3.1

CVE-2025-68836 - WordPress Table of Contents Creator plugin <= 1.6.4.1 - Reflected Cross Site Scripting (XSS) vulner…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator allows Reflected XSS.This issue affects Table of Contents Creator: from n/a through 1.6.4.1.

πŸ“… Published: March 19, 2026, 8:33 a.m. πŸ”„ Last Modified: April 28, 2026, 4:14 p.m.

7.1

CVSS3.1

CVE-2025-67618 - WordPress Brookside theme <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Brookside allows Reflected XSS.This issue affects Brookside: from n/a through 1.4.

πŸ“… Published: March 19, 2026, 8:31 a.m. πŸ”„ Last Modified: April 28, 2026, 4:14 p.m.

6.5

CVSS3.1

CVE-2025-62043 - WordPress WPCasa plugin <= 1.4.1 - Cross Site Scripting (XSS) vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa allows DOM-Based XSS.This issue affects WPCasa: from n/a through 1.4.1.

πŸ“… Published: March 19, 2026, 8:25 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

9.8

CVSS3.1

CVE-2025-60237 - WordPress Finag theme <= 1.5.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.

πŸ“… Published: March 19, 2026, 8:14 a.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

9.8

CVSS3.1

CVE-2025-60233 - WordPress Zuut theme <= 1.4.2 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.

πŸ“… Published: March 19, 2026, 8:13 a.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

7.1

CVSS3.1

CVE-2025-53222 - WordPress tagDiv Opt-In Builder plugin <= 1.7.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Reflected XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.3.

πŸ“… Published: March 19, 2026, 8:10 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

0.0

CVE-2025-50001 - WordPress tagDiv Composer plugin <= 5.4.2 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.

πŸ“… Published: March 19, 2026, 8:07 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

0.0

CVE-2025-32223 - WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.

πŸ“… Published: March 19, 2026, 8:05 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

5.3

CVSS3.1

CVE-2026-3475 - Instant Popup Builder <= 1.1.7 - Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter

The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1.7. This is due to the handle_email_verification_page() function constructing a shortcode string from user-supplied GET parameters (token, email) and …

πŸ“… Published: March 19, 2026, 7:34 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

7.6

CVSS3.1

CVE-2024-42210 - HCL Unica Marketing Operations v12.1.8 and lower is affected by a Stored cross-site scripting (XSS)…

A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Β Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data within its later HTTP resp…

πŸ“… Published: March 19, 2026, 7:32 a.m. πŸ”„ Last Modified: March 23, 2026, 2:16 p.m.
Total resulsts: 348415
Page 974 of 34,842
Β« previous page Β» next page
Filters