Latest CVE Feed
-
8.8
HIGHCVE-2025-31038
Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs allows Privilege Escalation. This issue affects Essential Breadcrumbs: from n/a through 1.1.1.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-31036
Cross-Site Request Forgery (CSRF) vulnerability in WPSolr free WPSolr allows Privilege Escalation. This issue affects WPSolr: from n/a through 24.0.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.9
MEDIUMCVE-2025-31035
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Chris WP Editor.md – The Perfect WordPress Markdown Editor allows Stored XSS. This issue affects WP Editor.md – The Perfect WordPres... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-31034
Cross-Site Request Forgery (CSRF) vulnerability in AboZain Albanna Customize Login Page allows Cross Site Request Forgery. This issue affects Customize Login Page: from n/a through 1.1.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-31033
Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity allows Cross Site Request Forgery. This issue affects Buddypress Humanity: from n/a through 1.2.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2025-31032
Cross-Site Request Forgery (CSRF) vulnerability in Pagopar - Grupo M S.A. Pagopar – WooCommerce Gateway allows Stored XSS. This issue affects Pagopar – WooCommerce Gateway: from n/a through 2.7.1.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2025-31026
Cross-Site Request Forgery (CSRF) vulnerability in Austin Comment Validation Reloaded allows Stored XSS. This issue affects Comment Validation Reloaded: from n/a through 0.5.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-31023
Cross-Site Request Forgery (CSRF) vulnerability in Purab Seo Meta Tags allows Cross Site Request Forgery. This issue affects Seo Meta Tags: from n/a through 1.4.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-31020
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler allows Stored XSS. This issue affects Simple Spoiler: from n/a through 1.4.... Read more
Affected Products : simple_spoiler- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-31017
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Noakes Nav Menu Manager allows Stored XSS. This issue affects Nav Menu Manager: from n/a through 3.2.5.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-31012
Missing Authorization vulnerability in Phil Age Gate allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Age Gate: from n/a through 3.5.4.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-31009
Server-Side Request Forgery (SSRF) vulnerability in Jan Boddez IndieBlocks allows Server Side Request Forgery. This issue affects IndieBlocks: from n/a through 0.13.1.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Server-Side Request Forgery
-
5.9
MEDIUMCVE-2025-31008
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YouTube Embed Plugin Support YouTube Embed allows Stored XSS. This issue affects YouTube Embed: from n/a through 5.3.1.... Read more
Affected Products : youtube_embed- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-31005
Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts allows Cross Site Request Forgery. This issue affects Easyfonts: from n/a through 1.1.2.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-31004
Missing Authorization vulnerability in Croover.inc Rich Table of Contents allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rich Table of Contents: from n/a through 1.4.0.... Read more
Affected Products : rich_table_of_contents- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
2.7
LOWCVE-2025-31003
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze allows Retrieve Embedded Sensitive Data. This issue affects Squeeze: from n/a through 1.6.... Read more
Affected Products : squeeze- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-31002
Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Using Malicious Files. This issue affects Squeeze: from n/a through 1.6.... Read more
Affected Products : squeeze- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
-
6.5
MEDIUMCVE-2025-32381
XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to 0.1.18, Xgrammar includes a cache for compiled grammars to increase performance with repeated use of the same grammar. This cache is held in memory. S... Read more
Affected Products : xgrammar- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-32380
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router's usage of Apollo Compiler allowed queries with deeply nested and reused ... Read more
Affected Products : apollo_router- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Denial of Service
-
5.0
MEDIUMCVE-2025-32379
Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app. This issue is pat... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting