CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-28886

Description: Cross-Site Request Forgery (CSRF) vulnerability in xjb REST API TO MiniProgram allows Cross Site Request Forgery. This issue affects REST API TO MiniProgram: from n/a through 4.7.1.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
March 11th, 2025 (4 months ago)

CVE-2025-28884

Description: Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator allows Cross Site Request Forgery. This issue affects WP Bulk Post Duplicator: from n/a through 1.2.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
March 11th, 2025 (4 months ago)

CVE-2025-28883

Description: Cross-Site Request Forgery (CSRF) vulnerability in Martin WP Compare Tables allows Stored XSS. This issue affects WP Compare Tables: from n/a through 1.0.5.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
March 11th, 2025 (4 months ago)

CVE-2025-28881

Description: Cross-Site Request Forgery (CSRF) vulnerability in mg12 Mobile Themes allows Cross Site Request Forgery. This issue affects Mobile Themes: from n/a through 1.1.1.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
March 11th, 2025 (4 months ago)

CVE-2025-28879

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aumsrini Bee Layer Slider allows Stored XSS. This issue affects Bee Layer Slider: from n/a through 1.1.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
March 11th, 2025 (4 months ago)

CVE-2025-28878

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will Brubaker Awesome Surveys allows Stored XSS. This issue affects Awesome Surveys: from n/a through 2.0.10.

CVSS: MEDIUM (5.9)

EPSS Score: 0.04%

Source: CVE
March 11th, 2025 (4 months ago)

CVE-2025-28876

Description: Cross-Site Request Forgery (CSRF) vulnerability in Skrill_Team Skrill Official allows Cross Site Request Forgery. This issue affects Skrill Official: from n/a through 1.0.65.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
March 11th, 2025 (4 months ago)

CVE-2025-28875

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates allows Stored XSS. This issue affects BP Email Assign Templates: from n/a through 1.6.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
March 11th, 2025 (4 months ago)

CVE-2025-28874

Description: Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BP Email Assign Templates: from n/a through 1.6.

CVSS: MEDIUM (6.5)

EPSS Score: 0.05%

Source: CVE
March 11th, 2025 (4 months ago)

CVE-2025-28872

Description: Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Block Spam By Math Reloaded: from n/a through 2.2.4.

CVSS: MEDIUM (5.3)

EPSS Score: 0.06%

Source: CVE
March 11th, 2025 (4 months ago)