CVE-2025-30782 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite allows PHP Local File Inclusion. This issue affects Subscribe to Download Lite: from n/a through 1.2.9.
CVSS: HIGH (7.5) EPSS Score: 0.13%
April 1st, 2025 (3 months ago)
|
CVE-2025-30774 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7.
CVSS: HIGH (8.2) EPSS Score: 0.03%
April 1st, 2025 (3 months ago)
|
CVE-2025-30622 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in torsteino PostMash allows SQL Injection. This issue affects PostMash: from n/a through 1.0.3.
CVSS: CRITICAL (9.3) EPSS Score: 0.04%
April 1st, 2025 (3 months ago)
|
CVE-2025-30614 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haozhe Xie Google Font Fix allows Reflected XSS. This issue affects Google Font Fix: from n/a through 2.3.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (3 months ago)
|
CVE-2025-30613 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N-Media Nmedia MailChimp allows Stored XSS. This issue affects Nmedia MailChimp: from n/a through 5.4.
CVSS: MEDIUM (6.5) EPSS Score: 0.03%
April 1st, 2025 (3 months ago)
|
CVE-2025-30607 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Name.ly Quick Localization allows Reflected XSS. This issue affects Quick Localization: from n/a through 0.1.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (3 months ago)
|
CVE-2025-30594 |
Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound Include URL allows Path Traversal. This issue affects Include URL: from n/a through 0.3.5.
CVSS: MEDIUM (6.5) EPSS Score: 0.05%
April 1st, 2025 (3 months ago)
|
CVE-2025-30589 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Flickr set slideshows allows SQL Injection. This issue affects Flickr set slideshows: from n/a through 0.9.
CVSS: HIGH (8.5) EPSS Score: 0.03%
April 1st, 2025 (3 months ago)
|
CVE-2025-30579 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakeii Pesapal Gateway for Woocommerce allows Reflected XSS. This issue affects Pesapal Gateway for Woocommerce: from n/a through 2.1.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (3 months ago)
|
CVE-2025-30563 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tidekey allows Reflected XSS. This issue affects Tidekey: from n/a through 1.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
April 1st, 2025 (3 months ago)
|