CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-32167

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devsoftbaltic SurveyJS allows Stored XSS. This issue affects SurveyJS: from n/a through 1.12.20.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32166

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in John Housholder Emma for WordPress allows Stored XSS. This issue affects Emma for WordPress: from n/a through 1.3.3.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32165

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fromdoppler Doppler Forms allows Stored XSS. This issue affects Doppler Forms: from n/a through 2.4.5.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32163

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS. This issue affects Xpro Elementor Addons: from n/a through 1.4.9.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32162

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32161

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks allows Stored XSS. This issue affects Arkhe Blocks: from n/a through 2.27.1.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32138

Description: Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps allows XML Injection. This issue affects Easy Google Maps: from n/a through 1.11.17.

CVSS: MEDIUM (6.6)

EPSS Score: 0.06%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32137

Description: Relative Path Traversal vulnerability in Cristián Lávaque s2Member allows Path Traversal. This issue affects s2Member: from n/a through 250214.

CVSS: MEDIUM (4.9)

EPSS Score: 0.05%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32136

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign allows Stored XSS. This issue affects ActiveCampaign: from n/a through 8.1.16.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32135

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rocketelements Split Test For Elementor allows Stored XSS. This issue affects Split Test For Elementor: from n/a through 1.8.3.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)