Latest CVE Feed
-
7.1
HIGHCVE-2025-28882
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omnify, Inc. Omnify allows Reflected XSS. This issue affects Omnify: from n/a through 2.0.3.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-28880
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Blue Captcha allows Reflected XSS. This issue affects Blue Captcha: from n/a through 1.7.4.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-28877
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Key4ce osTicket Bridge allows Reflected XSS. This issue affects Key4ce osTicket Bridge: from n/a through 1.4.0.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2025-28873
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Shuffle allows Blind SQL Injection. This issue affects Shuffle: from n/a through 0.5.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-28869
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NextGEN Gallery Voting allows Reflected XSS. This issue affects NextGEN Gallery Voting: from n/a through 2.7.6.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-28865
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lionelroux WP Colorful Tag Cloud allows Reflected XSS. This issue affects WP Colorful Tag Cloud: from n/a through 2.0.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-28858
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Maps allows Reflected XSS. This issue affects Arrow Maps: from n/a through 1.0.9.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-28855
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Teleport allows Reflected XSS. This issue affects Teleport: from n/a through 1.2.4.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-27404
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript i... Read more
Affected Products : icinga_web_2- Published: Mar. 26, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-27267
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in srcoley Random Quotes allows Reflected XSS. This issue affects Random Quotes: from n/a through 1.3.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-27015
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a before 30.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-27014
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko allows Reflected XSS.This issue affects Hostiko: from n/a before 30.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-26986
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Pearl - Corporate Business allows PHP Local File Inclusion.This issue affects Pearl - Corporate Business: from n/a befo... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
9.3
CRITICALCVE-2025-26941
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin allows SQL Injection.This issue affects Church Admin: from n/a through 5.0.18.... Read more
Affected Products : church_admin- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
-
5.9
MEDIUMCVE-2025-26929
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NOUS Ouvert Utile et Simple Accounting for WooCommerce allows Stored XSS.This issue affects Accounting for WooCommerce: from n/a through 1.6.8.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26923
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows Stored XSS.This issue affects Event post: from n/a through 5.9.8.... Read more
Affected Products : event_post- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26922
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techthemes AuraMart allows Stored XSS.This issue affects AuraMart: from n/a through 2.0.7.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26869
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Build allows Stored XSS.This issue affects Build: from n/a through 1.0.3.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26747
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26739
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefunction newseqo allows Stored XSS.This issue affects newseqo: from n/a through 2.1.1.... Read more
Affected Products :- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting