Latest CVE Feed
-
7.1
HIGHCVE-2025-25132
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ravi Singh Visitor Details allows Stored XSS. This issue affects Visitor Details: from n/a through 1.0.1.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-25131
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound RJ Quickcharts allows Stored XSS. This issue affects RJ Quickcharts: from n/a through 0.6.1.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-25130
Relative Path Traversal vulnerability in NotFound Delete Comments By Status allows PHP Local File Inclusion. This issue affects Delete Comments By Status: from n/a through 2.1.1.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-25129
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Callback Request allows Reflected XSS. This issue affects Callback Request: from n/a through 1.4.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25127
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rohitashv Singhal Contact Us By Lord Linus allows Reflected XSS. This issue affects Contact Us By Lord Linus: from n/a through 2.6.... Read more
Affected Products : contact_us- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25124
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devu Status Updater allows Reflected XSS. This issue affects Status Updater: from n/a through 1.9.2.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-25122
Path Traversal vulnerability in NotFound WizShop allows PHP Local File Inclusion. This issue affects WizShop: from n/a through 3.0.2.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-25121
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Theme Options Z allows Stored XSS. This issue affects Theme Options Z: from n/a through 1.4.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25119
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Woocommerce osCommerce Sync allows Reflected XSS. This issue affects Woocommerce osCommerce Sync: from n/a through 2.0.20.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25118
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Top Bar – PopUps – by WPOptin allows Reflected XSS. This issue affects Top Bar – PopUps – by WPOptin: from n/a through 2.0.8.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-25115
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Like dislike plus counter allows Stored XSS. This issue affects Like dislike plus counter: from n/a through 1.0.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25114
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role allows Reflected XSS. This issue affects User Role: from n/a through 1.0.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25113
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Implied Cookie Consent allows Reflected XSS. This issue affects Implied Cookie Consent: from n/a through 1.3.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-25112
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Social Links allows Blind SQL Injection. This issue affects Social Links: from n/a through 1.2.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-25109
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound WP Vehicle Manager allows PHP Local File Inclusion. This issue affects WP Vehicle Manager: from n/a through 3.1.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-25108
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shalomworld SW Plus allows Reflected XSS. This issue affects SW Plus: from n/a through 2.1.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25102
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Yahoo BOSS allows Reflected XSS. This issue affects Yahoo BOSS: from n/a through 0.7.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25099
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accreteinfosolution Appointment Buddy Widget allows Reflected XSS. This issue affects Appointment Buddy Widget: from n/a through 1.2.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25092
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-25090
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dreamstime Dreamstime Stock Photos dreamstime-stock-photos allows Reflected XSS.This issue affects Dreamstime Stock Photos: from n/a through 4.1.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting