CVE-2025-30916 |
Description: Missing Authorization vulnerability in enituretechnology Residential Address Detection allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Residential Address Detection: from n/a through 2.5.4.
CVSS: MEDIUM (6.5) EPSS Score: 0.05%
April 3rd, 2025 (3 months ago)
|
CVE-2025-30915 |
Description: Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through 5.2.19.
CVSS: MEDIUM (6.5) EPSS Score: 0.05%
April 3rd, 2025 (3 months ago)
|
CVE-2025-30908 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in Shamalli Web Directory Free allows Stored XSS. This issue affects Web Directory Free: from n/a through 1.7.6.
CVSS: HIGH (7.1) EPSS Score: 0.02%
April 3rd, 2025 (3 months ago)
|
CVE-2025-30889 |
Description: Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider allows Object Injection. This issue affects Testimonial Slider: from n/a through 2.0.13.
CVSS: HIGH (8.8) EPSS Score: 0.05%
April 3rd, 2025 (3 months ago)
|
CVE-2025-30858 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm allows Reflected XSS. This issue affects Snow Storm: from n/a through 1.4.6.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 3rd, 2025 (3 months ago)
|
CVE-2025-30616 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Latest Custom Post Type Updates allows Reflected XSS. This issue affects Latest Custom Post Type Updates: from n/a through 1.3.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 3rd, 2025 (3 months ago)
|
CVE-2025-30611 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Wptobe-signinup allows Reflected XSS. This issue affects Wptobe-signinup: from n/a through 1.1.2.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 3rd, 2025 (3 months ago)
|
CVE-2025-30596 |
Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound include-file allows Path Traversal. This issue affects include-file: from n/a through 1.
CVSS: MEDIUM (6.5) EPSS Score: 0.05%
April 3rd, 2025 (3 months ago)
|
CVE-2024-9416 |
Description: The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions <= 5.0.36) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.03%
April 3rd, 2025 (3 months ago)
|
CVE-2025-2299 |
Description: The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.10. This is due to missing or incorrect nonce validation on the 'ajaxEdit' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS: MEDIUM (6.1) EPSS Score: 0.04%
April 3rd, 2025 (3 months ago)
|