Latest CVE Feed
-
7.1
HIGHCVE-2025-23603
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Group category creator allows Reflected XSS. This issue affects Group category creator: from n/a through 1.3.0.3.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23602
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EELV Newsletter allows Reflected XSS. This issue affects EELV Newsletter: from n/a through 4.8.2.... Read more
Affected Products : eelv_newsletter- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23601
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tab My Content allows Reflected XSS. This issue affects Tab My Content: from n/a through 1.0.0.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23597
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Riosis Private Limited Rio Photo Gallery allows Reflected XSS. This issue affects Rio Photo Gallery: from n/a through 0.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23592
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound dForms allows Reflected XSS. This issue affects dForms: from n/a through 1.0.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23589
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ContentOptin Lite allows Reflected XSS. This issue affects ContentOptin Lite: from n/a through 1.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23583
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Explara Explara Membership allows Reflected XSS. This issue affects Explara Membership: from n/a through 0.0.7.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23578
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Custom CSS Addons allows Reflected XSS. This issue affects Custom CSS Addons: from n/a through 1.9.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
5.8
MEDIUMCVE-2025-23562
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound XLSXviewer allows Path Traversal. This issue affects XLSXviewer: from n/a through 2.1.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23548
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bilal TAS Responsivity allows Reflected XSS. This issue affects Responsivity: from n/a through 0.0.6.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23535
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in clickandsell REAL WordPress Sidebar allows Stored XSS. This issue affects REAL WordPress Sidebar: from n/a through 0.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.5
HIGHCVE-2025-23512
Missing Authorization vulnerability in Team118GROUP Team 118GROUP Agent allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Team 118GROUP Agent: from n/a through 1.6.0.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23509
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound HyperComments allows Reflected XSS. This issue affects HyperComments: from n/a through 0.9.6.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23507
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blrt Blrt WP Embed allows Reflected XSS. This issue affects Blrt WP Embed: from n/a through 1.6.9.... Read more
Affected Products : blrt_wp_embed- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23506
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP IMAP Auth allows Reflected XSS. This issue affects WP IMAP Auth: from n/a through 4.0.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23503
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Customizable Captcha and Contact Us allows Reflected XSS. This issue affects Customizable Captcha and Contact Us: from n/a through 1.0.2.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23500
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faaiq Ahmed, Technial Architect,[email protected] Simple Custom post type custom field allows Reflected XSS. This issue affects Simple Custom post type c... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23498
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Translation.Pro allows Reflected XSS. This issue affects Translation.Pro: from n/a through 1.0.0.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.1
HIGHCVE-2025-23495
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WooCommerce Order Search allows Reflected XSS. This issue affects WooCommerce Order Search: from n/a through 1.1.0.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
6.5
MEDIUMCVE-2025-23486
Missing Authorization vulnerability in NotFound Database Sync allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Database Sync: from n/a through 0.5.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025