4.6
CVE-2025-24459 -
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
7.1
CVE-2025-24458 -
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
5.5
CVE-2025-24457 -
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
6.7
CVE-2025-24456 -
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
0.0
CVE-2025-23996 - WordPress AnyRoad plugin <= 1.3.2 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in AnyRoad AnyRoad anyguide allows Cross Site Request Forgery.This issue affects AnyRoad: from n/a through <= 1.3.2.
0.0
CVE-2025-23994 - WordPress Estatebud โ Properties & Listings plugin <= 5.5.0 - CSRF to Settings Update & Stored XSS โฆ
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatebud Estatebud โ Properties & Listings estatebud-properties-listings allows Stored XSS.This issue affects Estatebud โ Properties & Listings: from n/a through <= 5.5.0.
0.0
CVE-2025-22722 - WordPress Widget Options plugin <= 4.0.8 - Broken Access Control to Notice Dimissal vulnerability
Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through <= 4.0.8.
0.0
CVE-2025-22721 - WordPress ApplyOnline plugin <= 2.6.7.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Farhan Noor ApplyOnline apply-online allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline: from n/a through <= 2.6.7.1.
0.0
CVE-2025-22661 - WordPress Online Payments plugin <= 3.20.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Payments โ Get Paid with PayPal, Square & Stripe paypal-payment-button-by-vcita allows Stored XSS.This issue affects Online Payments โ Get Paid with PayPal, Square & Stripe: from n/a tโฆ
0.0
CVE-2025-22276 - WordPress Related Post Shortcode Plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enguerranws Related Post Shortcode related-post-shortcode allows Stored XSS.This issue affects Related Post Shortcode: from n/a through <= 1.2.