CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-26552

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badrHan Naver Syndication V2 allows Stored XSS. This issue affects Naver Syndication V2: from n/a through 0.8.3.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
February 14th, 2025 (4 months ago)

CVE-2025-26551

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Bootstrap collapse allows Stored XSS. This issue affects Bootstrap collapse: from n/a through 1.0.4.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
February 14th, 2025 (4 months ago)

CVE-2025-26550

Description: Cross-Site Request Forgery (CSRF) vulnerability in Kunal Shivale Global Meta Keyword & Description allows Stored XSS. This issue affects Global Meta Keyword & Description: from n/a through 2.3.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
February 14th, 2025 (4 months ago)

CVE-2025-26549

Description: Cross-Site Request Forgery (CSRF) vulnerability in pa1 WP Html Page Sitemap allows Stored XSS. This issue affects WP Html Page Sitemap: from n/a through 2.2.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
February 14th, 2025 (4 months ago)

CVE-2025-26547

Description: Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin allows Stored XSS. This issue affects My Login Logout Plugin: from n/a through 2.4.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
February 14th, 2025 (4 months ago)

CVE-2025-26545

Description: Cross-Site Request Forgery (CSRF) vulnerability in shisuh Related Posts Line-up-Exactly by Milliard allows Stored XSS. This issue affects Related Posts Line-up-Exactly by Milliard: from n/a through 0.0.22.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
February 14th, 2025 (4 months ago)

CVE-2025-26543

Description: Cross-Site Request Forgery (CSRF) vulnerability in Pukhraj Suthar Simple Responsive Menu allows Stored XSS. This issue affects Simple Responsive Menu: from n/a through 2.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
February 14th, 2025 (4 months ago)

CVE-2025-26539

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petkivim Embed Google Map allows Stored XSS. This issue affects Embed Google Map: from n/a through 3.2.

CVSS: MEDIUM (6.5)

EPSS Score: 0.04%

Source: CVE
February 14th, 2025 (4 months ago)

CVE-2025-26538

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Prezi Embedder allows Stored XSS. This issue affects Prezi Embedder: from n/a through 2.1.

CVSS: MEDIUM (6.5)

EPSS Score: 0.04%

Source: CVE
February 14th, 2025 (4 months ago)

CVE-2025-0837

Description: The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

EPSS Score: 0.05%

Source: CVE
February 14th, 2025 (4 months ago)