CVE-2025-30794 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Events Calendar Event Tickets allows Reflected XSS. This issue affects Event Tickets: from n/a through 5.20.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (21 days ago)
|
CVE-2025-30793 |
Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed allows Path Traversal. This issue affects Houzez Property Feed: from n/a through 2.5.4.
CVSS: HIGH (7.5) EPSS Score: 0.06%
April 1st, 2025 (21 days ago)
|
CVE-2025-30782 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite allows PHP Local File Inclusion. This issue affects Subscribe to Download Lite: from n/a through 1.2.9.
CVSS: HIGH (7.5) EPSS Score: 0.13%
April 1st, 2025 (21 days ago)
|
CVE-2025-30774 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7.
CVSS: HIGH (8.2) EPSS Score: 0.03%
April 1st, 2025 (21 days ago)
|
CVE-2025-30614 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haozhe Xie Google Font Fix allows Reflected XSS. This issue affects Google Font Fix: from n/a through 2.3.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (21 days ago)
|
CVE-2025-30607 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Name.ly Quick Localization allows Reflected XSS. This issue affects Quick Localization: from n/a through 0.1.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (21 days ago)
|
CVE-2025-30589 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Flickr set slideshows allows SQL Injection. This issue affects Flickr set slideshows: from n/a through 0.9.
CVSS: HIGH (8.5) EPSS Score: 0.03%
April 1st, 2025 (21 days ago)
|
CVE-2025-30579 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakeii Pesapal Gateway for Woocommerce allows Reflected XSS. This issue affects Pesapal Gateway for Woocommerce: from n/a through 2.1.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (21 days ago)
|
CVE-2025-30563 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tidekey allows Reflected XSS. This issue affects Tidekey: from n/a through 1.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (21 days ago)
|
CVE-2025-30559 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Kento WordPress Stats allows Stored XSS. This issue affects Kento WordPress Stats: from n/a through 1.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (21 days ago)
|