CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-46254

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through 45.10.0.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46253

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit allows Stored XSS. This issue affects GutenKit: from n/a through 2.2.2.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46252

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kofimokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46251

Description: Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants Table Reservations and Take-Away allows Cross Site Request Forgery. This issue affects VikRestaurants Table Reservations and Take-Away: from n/a through 1.3.3.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46250

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Stored XSS. This issue affects VForm: from n/a through 3.1.14.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46249

Description: Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.4.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46247

Description: Missing Authorization vulnerability in codepeople Appointment Booking Calendar allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Appointment Booking Calendar: from n/a through 1.3.92.

CVSS: MEDIUM (5.3)

EPSS Score: 0.06%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46246

Description: Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers allows Cross Site Request Forgery. This issue affects CM Answers: from n/a through 3.3.3.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46245

Description: Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer allows Cross Site Request Forgery. This issue affects CM Ad Changer: from n/a through 2.0.5.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
April 22nd, 2025 (about 2 months ago)

CVE-2025-46244

Description: Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced Linked Variations for Woocommerce: from n/a through 1.0.3.

CVSS: MEDIUM (5.3)

EPSS Score: 0.04%

Source: CVE
April 22nd, 2025 (about 2 months ago)