CVE-2025-22267 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruce Wampler Weaver Themes Shortcode Compatibility allows Stored XSS. This issue affects Weaver Themes Shortcode Compatibility: from n/a through 1.0.4.
CVSS: MEDIUM (6.5) EPSS Score: 0.04%
January 22nd, 2025 (5 months ago)
|
CVE-2025-22262 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bonjour Bar allows Stored XSS. This issue affects Bonjour Bar: from n/a through 1.0.0.
CVSS: MEDIUM (5.9) EPSS Score: 0.04%
January 22nd, 2025 (5 months ago)
|
CVE-2025-0450 |
Description: The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality in all versions up to, and including, 27.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.05%
January 22nd, 2025 (5 months ago)
|
CVE-2025-0371 |
Description: The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.05%
January 22nd, 2025 (5 months ago)
|
CVE-2024-56277 |
Description: Improper Encoding or Escaping of Output vulnerability in Poll Maker Team Poll Maker. This issue affects Poll Maker: from n/a through n/a.
CVSS: MEDIUM (5.3) EPSS Score: 0.04%
January 22nd, 2025 (5 months ago)
|
CVE-2024-51919 |
Description: Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.
CVSS: CRITICAL (9.0) EPSS Score: 0.04%
January 22nd, 2025 (5 months ago)
|
CVE-2024-51888 |
Description: Incorrect Privilege Assignment vulnerability in NotFound Homey Login Register allows Privilege Escalation. This issue affects Homey Login Register: from n/a through 2.4.0.
CVSS: CRITICAL (9.8) EPSS Score: 0.04%
January 22nd, 2025 (5 months ago)
|
CVE-2024-51818 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.
CVSS: CRITICAL (9.3) EPSS Score: 0.04%
January 22nd, 2025 (5 months ago)
|
CVE-2024-49700 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ARPrice allows Reflected XSS. This issue affects ARPrice: from n/a through 4.0.3.
CVSS: HIGH (7.1) EPSS Score: 0.04%
January 22nd, 2025 (5 months ago)
|
CVE-2024-49699 |
Description: Deserialization of Untrusted Data vulnerability in NotFound ARPrice allows Object Injection. This issue affects ARPrice: from n/a through 4.0.3.
CVSS: HIGH (8.8) EPSS Score: 0.04%
January 22nd, 2025 (5 months ago)
|