Latest CVE Feed
-
8.5
HIGHCVE-2025-28873
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Shuffle allows Blind SQL Injection. This issue affects Shuffle: from n/a through 0.5.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-28869
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NextGEN Gallery Voting allows Reflected XSS. This issue affects NextGEN Gallery Voting: from n/a through 2.7.6.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-28865
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lionelroux WP Colorful Tag Cloud allows Reflected XSS. This issue affects WP Colorful Tag Cloud: from n/a through 2.0.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-28858
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Maps allows Reflected XSS. This issue affects Arrow Maps: from n/a through 1.0.9.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-28855
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Teleport allows Reflected XSS. This issue affects Teleport: from n/a through 1.2.4.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-27404
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript i... Read more
Affected Products : icinga_web_2- Published: Mar. 26, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-27267
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in srcoley Random Quotes allows Reflected XSS. This issue affects Random Quotes: from n/a through 1.3.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-27015
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a before 30.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-27014
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko allows Reflected XSS.This issue affects Hostiko: from n/a before 30.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-26986
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Pearl - Corporate Business allows PHP Local File Inclusion.This issue affects Pearl - Corporate Business: from n/a befo... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
9.3
CRITICALCVE-2025-26941
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin allows SQL Injection.This issue affects Church Admin: from n/a through 5.0.18.... Read more
Affected Products : church_admin- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
-
5.9
MEDIUMCVE-2025-26929
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NOUS Ouvert Utile et Simple Accounting for WooCommerce allows Stored XSS.This issue affects Accounting for WooCommerce: from n/a through 1.6.8.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26923
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows Stored XSS.This issue affects Event post: from n/a through 5.9.8.... Read more
Affected Products : event_post- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26922
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techthemes AuraMart allows Stored XSS.This issue affects AuraMart: from n/a through 2.0.7.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26869
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Build allows Stored XSS.This issue affects Build: from n/a through 1.0.3.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26747
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26739
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefunction newseqo allows Stored XSS.This issue affects newseqo: from n/a through 2.1.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26584
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound TBTestimonials allows Reflected XSS. This issue affects TBTestimonials: from n/a through 1.7.3.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26583
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Video Share VOD allows Reflected XSS. This issue affects Video Share VOD: from n/a through 2.7.2.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26581
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Picture Gallery allows Reflected XSS. This issue affects Picture Gallery: from n/a through 1.6.2.... Read more
Affected Products : picture_gallery- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting