Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-49074

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemesGrove WidgetKit allows Stored XSS.This issue affects WidgetKit: from n/a through 2.5.4.

CVSS: MEDIUM (6.5)

Source: CVE
June 6th, 2025 (about 15 hours ago)

CVE-2025-49068

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.4.8.

CVSS: MEDIUM (6.5)

Source: CVE
June 6th, 2025 (about 15 hours ago)

CVE-2025-49067

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Nasa Core allows Stored XSS.This issue affects Nasa Core: from n/a before 6.4.1.

CVSS: MEDIUM (6.5)

Source: CVE
June 6th, 2025 (about 15 hours ago)

CVE-2025-48337

Description: Missing Authorization vulnerability in QuickcabWP QuickCab.This issue affects QuickCab: from n/a through 1.3.3.

CVSS: MEDIUM (5.3)

Source: CVE
June 6th, 2025 (about 15 hours ago)

CVE-2025-48335

Description: Missing Authorization vulnerability in CyberChimps Responsive Plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Plus: from n/a through 3.2.0.

CVSS: MEDIUM (5.4)

Source: CVE
June 6th, 2025 (about 15 hours ago)

CVE-2025-48328

Description: Cross-Site Request Forgery (CSRF) vulnerability in Daman Jeet Real Time Validation for Gravity Forms allows Cross Site Request Forgery.This issue affects Real Time Validation for Gravity Forms: from n/a through 1.7.0.

CVSS: MEDIUM (4.3)

Source: CVE
June 6th, 2025 (about 15 hours ago)

CVE-2025-5703

Description: The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all versions up to, and including, 10.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

Source: CVE
June 6th, 2025 (about 20 hours ago)

CVE-2025-5699

Description: The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2015.0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS: MEDIUM (5.5)

Source: CVE
June 6th, 2025 (about 20 hours ago)

CVE-2025-5686

Description: The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

Source: CVE
June 6th, 2025 (about 20 hours ago)

CVE-2025-5586

Description: The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

Source: CVE
June 6th, 2025 (about 20 hours ago)