CVE-2025-26546 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Cookies Pro allows Reflected XSS. This issue affects Cookies Pro: from n/a through 1.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
March 26th, 2025 (3 months ago)
|
CVE-2025-26544 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound UTM tags tracking for Contact Form 7 allows Reflected XSS. This issue affects UTM tags tracking for Contact Form 7: from n/a through 2.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
March 26th, 2025 (3 months ago)
|
CVE-2025-26542 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Zalo Live Chat allows Reflected XSS. This issue affects Zalo Live Chat: from n/a through 1.1.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
March 26th, 2025 (3 months ago)
|
CVE-2025-26541 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce allows Reflected XSS. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through 1.7.6.
CVSS: HIGH (7.1) EPSS Score: 0.04%
March 26th, 2025 (3 months ago)
|
CVE-2025-26536 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yendif Player Another Events Calendar allows Reflected XSS. This issue affects Another Events Calendar: from n/a through 1.7.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
March 26th, 2025 (3 months ago)
|
CVE-2025-25134 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Theme Demo Bar allows Reflected XSS. This issue affects Theme Demo Bar: from n/a through 1.6.3.
CVSS: HIGH (7.1) EPSS Score: 0.04%
March 26th, 2025 (3 months ago)
|
CVE-2025-24690 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality allows PHP Local File Inclusion. This issue affects Formality: from n/a through 1.5.7.
CVSS: HIGH (8.1) EPSS Score: 0.13%
March 26th, 2025 (3 months ago)
|
CVE-2025-23964 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Google Plus allows Reflected XSS. This issue affects Google Plus: from n/a through 1.0.2.
CVSS: HIGH (7.1) EPSS Score: 0.04%
March 26th, 2025 (3 months ago)
|
CVE-2025-23952 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget allows PHP Local File Inclusion. This issue affects custom-field-list-widget: from n/a through 1.5.1.
CVSS: HIGH (8.1) EPSS Score: 0.13%
March 26th, 2025 (3 months ago)
|
CVE-2025-23937 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound LinkedIn Lite allows PHP Local File Inclusion. This issue affects LinkedIn Lite: from n/a through 1.0.
CVSS: HIGH (8.1) EPSS Score: 0.13%
March 26th, 2025 (3 months ago)
|