Latest CVE Feed
-
7.1
HIGHCVE-2025-26579
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper MicroPayments allows Reflected XSS. This issue affects MicroPayments: from n/a through 3.1.6.... Read more
Affected Products : micropayments- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26576
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in takumin WP Simple Slideshow allows Reflected XSS. This issue affects WP Simple Slideshow: from n/a through 1.0.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26575
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Maurer Display Post Meta allows Reflected XSS. This issue affects Display Post Meta: from n/a through 2.4.4.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26573
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Rizzi Guestbook allows Reflected XSS. This issue affects Rizzi Guestbook: from n/a through 4.0.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26566
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound In Stock Mailer for WooCommerce allows Reflected XSS. This issue affects In Stock Mailer for WooCommerce: from n/a through 2.1.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26565
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kagla GNUPress allows Reflected XSS. This issue affects GNUPress: from n/a through 0.2.9.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26564
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kagla GNUCommerce allows Reflected XSS. This issue affects GNUCommerce: from n/a through 1.5.4.... Read more
Affected Products : gnucommerce- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26560
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Contact Form III allows Reflected XSS. This issue affects WP Contact Form III: from n/a through 1.6.2d.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26559
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Secure Invites allows Reflected XSS. This issue affects Secure Invites: from n/a through 1.3.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26546
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Cookies Pro allows Reflected XSS. This issue affects Cookies Pro: from n/a through 1.0.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26544
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound UTM tags tracking for Contact Form 7 allows Reflected XSS. This issue affects UTM tags tracking for Contact Form 7: from n/a through 2.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26542
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Zalo Live Chat allows Reflected XSS. This issue affects Zalo Live Chat: from n/a through 1.1.0.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26541
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce allows Reflected XSS. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: fr... Read more
Affected Products : bitcoin_\/_altcoin_payment_gateway_for_woocommerce- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26537
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound GDPR Tools allows Stored XSS. This issue affects GDPR Tools: from n/a through 1.0.2.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26536
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yendif Player Another Events Calendar allows Reflected XSS. This issue affects Another Events Calendar: from n/a through 1.7.0.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25134
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Theme Demo Bar allows Reflected XSS. This issue affects Theme Demo Bar: from n/a through 1.6.3.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-24972
Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, in specific circumstances, users could be added to group direct messages despite disabling direct messaging in their ... Read more
Affected Products : discourse- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-24690
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality allows PHP Local File Inclusion. This issue affects Formality: from n/a through 1.5.7.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-23964
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Google Plus allows Reflected XSS. This issue affects Google Plus: from n/a through 1.0.2.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-23952
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget allows PHP Local File Inclusion. This issue affects custom-field-list-widget: from n/a through 1.5.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal