Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-46254

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through 45.10.0.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46253

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit allows Stored XSS. This issue affects GutenKit: from n/a through 2.2.2.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46250

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Stored XSS. This issue affects VForm: from n/a through 3.1.14.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46249

Description: Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.4.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46247

Description: Missing Authorization vulnerability in codepeople Appointment Booking Calendar allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Appointment Booking Calendar: from n/a through 1.3.92.

CVSS: MEDIUM (5.3)

EPSS Score: 0.06%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46246

Description: Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers allows Cross Site Request Forgery. This issue affects CM Answers: from n/a through 3.3.3.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46245

Description: Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer allows Cross Site Request Forgery. This issue affects CM Ad Changer: from n/a through 2.0.5.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46244

Description: Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced Linked Variations for Woocommerce: from n/a through 1.0.3.

CVSS: MEDIUM (5.3)

EPSS Score: 0.04%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46243

Description: Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce allows Cross Site Request Forgery. This issue affects Recover abandoned cart for WooCommerce: from n/a through 2.2.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46240

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter allows Stored XSS. This issue affects Simple Download Counter: from n/a through 2.2.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 22nd, 2025 (about 2 months ago)