CVE-2025-23506 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP IMAP Auth allows Reflected XSS. This issue affects WP IMAP Auth: from n/a through 4.0.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|
CVE-2025-23503 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Customizable Captcha and Contact Us allows Reflected XSS. This issue affects Customizable Captcha and Contact Us: from n/a through 1.0.2.
CVSS: HIGH (7.1) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|
CVE-2025-23500 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faaiq Ahmed, Technial Architect,[email protected] Simple Custom post type custom field allows Reflected XSS. This issue affects Simple Custom post type custom field: from n/a through 1.0.3.
CVSS: HIGH (7.1) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|
CVE-2025-23498 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Translation.Pro allows Reflected XSS. This issue affects Translation.Pro: from n/a through 1.0.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|
CVE-2025-23495 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WooCommerce Order Search allows Reflected XSS. This issue affects WooCommerce Order Search: from n/a through 1.1.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|
CVE-2025-23486 |
Description: Missing Authorization vulnerability in NotFound Database Sync allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Database Sync: from n/a through 0.5.1.
CVSS: MEDIUM (6.5) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|
CVE-2025-23475 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound History timeline allows Reflected XSS. This issue affects History timeline: from n/a through 0.7.2.
CVSS: HIGH (7.1) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|
CVE-2025-23462 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound FWD Slider allows Reflected XSS. This issue affects FWD Slider: from n/a through 1.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|
CVE-2025-23449 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Simple shortcode buttons allows Reflected XSS. This issue affects Simple shortcode buttons: from n/a through 1.3.2.
CVSS: HIGH (7.1) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|
CVE-2025-23237 |
Description: Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected product, an arbitrary OS command may be executed.
CVSS: MEDIUM (6.6) EPSS Score: 0.04%
January 23rd, 2025 (6 months ago)
|