CVE-2025-23448 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dastan800 visualslider Sldier allows Reflected XSS. This issue affects visualslider Sldier: from n/a through 1.1.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 17th, 2025 (about 2 months ago)
|
CVE-2025-23443 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Claire Ryan Author Showcase allows Reflected XSS. This issue affects Author Showcase: from n/a through 1.4.3.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 17th, 2025 (about 2 months ago)
|
CVE-2025-22796 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in platcom WP-Asambleas allows Reflected XSS. This issue affects WP-Asambleas: from n/a through 2.85.0.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
April 17th, 2025 (about 2 months ago)
|
CVE-2025-22774 |
WordPress CRUDLab Scroll to Top Plugin <= 1.0.1 - Reflected Cross Site Scripting (XSS) vulnerability
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRUDLab CRUDLab Scroll to Top allows Reflected XSS. This issue affects CRUDLab Scroll to Top: from n/a through 1.0.1.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
April 17th, 2025 (about 2 months ago)
|
CVE-2025-22692 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rachanaS Sponsered Link allows Reflected XSS. This issue affects Sponsered Link: from n/a through 4.0.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
April 17th, 2025 (about 2 months ago)
|
CVE-2025-22651 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wppluginboxdev Stylish Google Sheet Reader allows Reflected XSS. This issue affects Stylish Google Sheet Reader: from n/a through 4.0.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
April 17th, 2025 (about 2 months ago)
|
CVE-2025-22636 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vicente Ruiz Gálvez VR-Frases allows Reflected XSS. This issue affects VR-Frases: from n/a through 3.0.1.
CVSS: HIGH (8.2) EPSS Score: 0.04% SSVC Exploitation: none
April 17th, 2025 (about 2 months ago)
|
CVE-2025-22565 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bill Zimmerman vooPlayer v4 allows Reflected XSS. This issue affects vooPlayer v4: from n/a through 4.0.4.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
April 17th, 2025 (about 2 months ago)
|
CVE-2025-3294 |
Description: The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which may make remote code execution possible assuming the files can be written to by the web server.
CVSS: HIGH (7.2) EPSS Score: 0.22%
April 17th, 2025 (about 2 months ago)
|
CVE-2024-13925 |
Description: The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the entire disk.
CVSS: HIGH (7.5) EPSS Score: 0.05%
April 17th, 2025 (about 2 months ago)
|