Latest CVE Feed
-
7.1
HIGHCVE-2025-31085
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-language allows Reflected XSS. This issue affects xili-language: from n/a through 2.21.2.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-31082
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack allows PHP Local File Inclusion. This issue affects News & Blog Designer Pack: from n/a through 4.... Read more
Affected Products : news_\&_blog_designer_pack- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-31081
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Reflected XSS. This issue affects Enable Media Replace: from n/a through 4.1.5.... Read more
Affected Products : enable_media_replace- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-31080
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms allows Stored XSS. This issue affects HTML Forms: from n/a through 1.5.1.... Read more
Affected Products : html_forms- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-31078
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows Reflected XSS. This issue affects Small Package Quotes – Worldwide Express Edit... Read more
Affected Products : small_package_quotes- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-30913
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in podpirate Access Areas allows Reflected XSS. This issue affects Access Areas: from n/a through 1.5.19.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-30906
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coffee Code Tech Plugin Oficial – Getnet para WooCommerce allows Reflected XSS. This issue affects Plugin Oficial – Getnet para WooCommerce: from n/a thr... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-30905
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from... Read more
Affected Products : secure_copy_content_protection_and_content_locking- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-30892
Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly allows Object Injection. This issue affects WpTravelly: from n/a through 1.8.7.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-30853
Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ShortPixel Adaptive Images: from n/a through 3.10.0.... Read more
Affected Products : shortpixel_adaptive_images- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-30852
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emotionalonlinestorytelling Oracle Cards Lite allows Reflected XSS. This issue affects Oracle Cards Lite: from n/a through 1.2.1.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-30844
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Watu Quiz allows Reflected XSS. This issue affects Watu Quiz: from n/a through 3.4.2.... Read more
Affected Products : watu_quiz- Published: Apr. 01, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
9.9
CRITICALCVE-2025-30841
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock allows Remote Code Inclusion. This issue affects Countdown & Clock: from n/a through 2.8.8.... Read more
Affected Products : countdown_builder- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-30825
Missing Authorization vulnerability in WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce allows Privilege Escalation. This issue affects WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce: from n/a through 1.3.5.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-30807
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martin Nguyen Next-Cart Store to WooCommerce Migration allows SQL Injection. This issue affects Next-Cart Store to WooCommerce Migration: from n/a throug... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-30778
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS. This issue affects VForm: from n/a through 3.1.9.... Read more
Affected Products : lifetime_free_drag_\&_drop_contact_form_builder- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-30580
Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound DigiWidgets Image Editor allows Remote Code Inclusion. This issue affects DigiWidgets Image Editor: from n/a through 1.10.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-30554
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Frizzly allows Reflected XSS. This issue affects Frizzly: from n/a through 1.1.0.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-29070
A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never c... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Denial of Service
-
6.3
MEDIUMCVE-2025-29049
Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting