CVE-2025-26552 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badrHan Naver Syndication V2 allows Stored XSS. This issue affects Naver Syndication V2: from n/a through 0.8.3.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26551 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Bootstrap collapse allows Stored XSS. This issue affects Bootstrap collapse: from n/a through 1.0.4.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26550 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in Kunal Shivale Global Meta Keyword & Description allows Stored XSS. This issue affects Global Meta Keyword & Description: from n/a through 2.3.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26549 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in pa1 WP Html Page Sitemap allows Stored XSS. This issue affects WP Html Page Sitemap: from n/a through 2.2.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26547 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin allows Stored XSS. This issue affects My Login Logout Plugin: from n/a through 2.4.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26545 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in shisuh Related Posts Line-up-Exactly by Milliard allows Stored XSS. This issue affects Related Posts Line-up-Exactly by Milliard: from n/a through 0.0.22.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26543 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in Pukhraj Suthar Simple Responsive Menu allows Stored XSS. This issue affects Simple Responsive Menu: from n/a through 2.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26539 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petkivim Embed Google Map allows Stored XSS. This issue affects Embed Google Map: from n/a through 3.2.
CVSS: MEDIUM (6.5) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26538 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Prezi Embedder allows Stored XSS. This issue affects Prezi Embedder: from n/a through 2.1.
CVSS: MEDIUM (6.5) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-0837 |
Description: The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.05%
February 14th, 2025 (4 months ago)
|