6.1

CVSS3.1

CVE-2025-39400 - WordPress User Registration plugin < 4.2.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through < 4.2.0.

πŸ“… Published: April 24, 2025, 4:08 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-39404 - WordPress Sassy Social Share plugin <= 3.3.73 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Phishing.This issue affects Sassy Social Share: from n/a through <= 3.3.73.

πŸ“… Published: April 24, 2025, 4:08 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-39408 - WordPress BruteGuard – Brute Force Login Protection plugin <= 0.1.4 - Reflected Cross Site Scriptin…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress BruteGuard – Brute Force Login Protection bruteguard allows Reflected XSS.This issue affects BruteGuard – Brute Force Login Protection: from n/a through <= 0.1.4.

πŸ“… Published: April 24, 2025, 4:08 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46264 - WordPress PowerPress Podcasting <= 11.12.5 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload a Web Shell to a Web Server.This issue affects PowerPress Podcasting: from n/a through <= 11.12.5.

πŸ“… Published: April 24, 2025, 4:08 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46230 - WordPress Popup Builder plugin <= 1.1.35 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder easy-notify-lite allows PHP Local File Inclusion.This issue affects Popup Builder: from n/a through <= 1.1.35.

πŸ“… Published: April 24, 2025, 4:08 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46234 - WordPress Control Listings plugin <= 1.0.4.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Habibur Rahman Razib Control Listings control-listings allows Reflected XSS.This issue affects Control Listings: from n/a through <= 1.0.4.1.

πŸ“… Published: April 24, 2025, 4:08 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46248 - WordPress Frontend Dashboard plugin <= 2.2.5 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows SQL Injection.This issue affects Frontend Dashboard: from n/a through <= 2.2.5.

πŸ“… Published: April 24, 2025, 4:08 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46260 - WordPress Sky Addons for Elementor plugin <= 3.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor sky-elementor-addons allows Stored XSS.This issue affects Sky Addons for Elementor: from n/a through <= 3.0.1.

πŸ“… Published: April 24, 2025, 4:08 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

4.8

CVSS3.1

CVE-2025-46261 - WordPress Seriously Simple Podcasting plugin <= 3.9.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.9.0.

πŸ“… Published: April 24, 2025, 4:08 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

8.7

CVSS4.0

CVE-2025-43855 - tRPC 11 WebSocket DoS Vulnerability

tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before 11.1.1, an unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash …

πŸ“… Published: April 24, 2025, 1:58 p.m. πŸ”„ Last Modified: May 14, 2025, 8:07 p.m.
Total resulsts: 344126
Page 5174 of 34,413
Β« previous page Β» next page
Filters