Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-28890

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Lightview Plus allows Reflected XSS. This issue affects Lightview Plus: from n/a through 3.1.3.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

SSVC Exploitation: none

Source: CVE
March 26th, 2025 (27 days ago)

CVE-2025-28889

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Custom Product Stickers for Woocommerce allows Reflected XSS. This issue affects Custom Product Stickers for Woocommerce: from n/a through 1.9.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

SSVC Exploitation: none

Source: CVE
March 26th, 2025 (27 days ago)

CVE-2025-28882

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omnify, Inc. Omnify allows Reflected XSS. This issue affects Omnify: from n/a through 2.0.3.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
March 26th, 2025 (27 days ago)

CVE-2025-28880

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Blue Captcha allows Reflected XSS. This issue affects Blue Captcha: from n/a through 1.7.4.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
March 26th, 2025 (27 days ago)

CVE-2025-28877

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Key4ce osTicket Bridge allows Reflected XSS. This issue affects Key4ce osTicket Bridge: from n/a through 1.4.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
March 26th, 2025 (27 days ago)

CVE-2025-28873

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Shuffle allows Blind SQL Injection. This issue affects Shuffle: from n/a through 0.5.

CVSS: HIGH (8.5)

EPSS Score: 0.03%

Source: CVE
March 26th, 2025 (27 days ago)

CVE-2025-28869

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NextGEN Gallery Voting allows Reflected XSS. This issue affects NextGEN Gallery Voting: from n/a through 2.7.6.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
March 26th, 2025 (27 days ago)

CVE-2025-28865

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lionelroux WP Colorful Tag Cloud allows Reflected XSS. This issue affects WP Colorful Tag Cloud: from n/a through 2.0.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
March 26th, 2025 (27 days ago)

CVE-2025-28858

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Maps allows Reflected XSS. This issue affects Arrow Maps: from n/a through 1.0.9.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
March 26th, 2025 (27 days ago)

CVE-2025-28855

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Teleport allows Reflected XSS. This issue affects Teleport: from n/a through 1.2.4.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
March 26th, 2025 (27 days ago)