Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-31445

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pages Order allows Reflected XSS. This issue affects Pages Order: from n/a through 1.1.3.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
April 1st, 2025 (20 days ago)

CVE-2025-31441

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in S WordPress Galleria allows Reflected XSS. This issue affects WordPress Galleria: from n/a through 1.4.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
April 1st, 2025 (20 days ago)

CVE-2025-31431

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Bookmarks allows Reflected XSS. This issue affects WP Bookmarks: from n/a through 1.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
April 1st, 2025 (20 days ago)

CVE-2025-31097

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ho3einie Material Dashboard allows PHP Local File Inclusion. This issue affects Material Dashboard: from n/a through 1.4.5.

CVSS: HIGH (8.1)

EPSS Score: 0.15%

Source: CVE
April 1st, 2025 (20 days ago)

CVE-2025-31089

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fahad Mahmood Order Splitter for WooCommerce allows SQL Injection. This issue affects Order Splitter for WooCommerce: from n/a through 5.3.0.

CVSS: HIGH (8.5)

EPSS Score: 0.03%

Source: CVE
April 1st, 2025 (20 days ago)

CVE-2025-31086

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick McReynolds Product Table by WBW allows Reflected XSS. This issue affects Product Table by WBW: from n/a through 2.1.4.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
April 1st, 2025 (20 days ago)

CVE-2025-31085

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-language allows Reflected XSS. This issue affects xili-language: from n/a through 2.21.2.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
April 1st, 2025 (20 days ago)

CVE-2025-31082

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack allows PHP Local File Inclusion. This issue affects News & Blog Designer Pack: from n/a through 4.0.

CVSS: HIGH (8.1)

EPSS Score: 0.14%

Source: CVE
April 1st, 2025 (20 days ago)

CVE-2025-31081

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Reflected XSS. This issue affects Enable Media Replace: from n/a through 4.1.5.

CVSS: HIGH (7.1)

EPSS Score: 0.03%

Source: CVE
April 1st, 2025 (20 days ago)

CVE-2025-31080

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms allows Stored XSS. This issue affects HTML Forms: from n/a through 1.5.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
April 1st, 2025 (20 days ago)