Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62943

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt McInvale Next Page, Not Next Post next-page-not-next-post allows Stored XSS.This issue affects Next Page, Not Next Post: from n/a through <= 0.3.0.

PUBLISHED
Vendor
Matt McInvale
Product
Next Page, Not Next Post
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62942

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tempranova WP Mapbox GL JS Maps wp-mapbox-gl-js allows Stored XSS.This issue affects WP Mapbox GL JS Maps: from n/a through <= 3.0.1.

PUBLISHED
Vendor
tempranova
Product
WP Mapbox GL JS Maps
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62941

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Events Maker by dFactory events-maker allows Stored XSS.This issue affects Events Maker by dFactory: from n/a through <= 1.6.14.

PUBLISHED
Vendor
dFactory
Product
Events Maker by dFactory
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62940

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Diego Blox Lite blox-lite allows Stored XSS.This issue affects Blox Lite: from n/a through <= 1.2.8.

PUBLISHED
Vendor
Nick Diego
Product
Blox Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6294

A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact.php. The manipulation of the argument hostel_name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Hostel Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-62939

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Open Currency Converter artiss-currency-converter allows Stored XSS.This issue affects Open Currency Converter: from n/a through <= 1.5.0.

PUBLISHED
Vendor
Joe
Product
Open Currency Converter
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62938

Missing Authorization vulnerability in Reoon Technology Reoon Email Verifier reoon-email-verifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reoon Email Verifier: from n/a through <= 2.0.1.

PUBLISHED
Vendor
Reoon Technology
Product
Reoon Email Verifier
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62937

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johnny Post List Featured Image post-list-featured-image allows Stored XSS.This issue affects Post List Featured Image: from n/a through <= 0.5.9.

PUBLISHED
Vendor
Johnny
Product
Post List Featured Image
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62936

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Jthemes xSmart xsmart allows Code Injection.This issue affects xSmart: from n/a through <= 1.2.9.4.

PUBLISHED
Vendor
Jthemes
Product
xSmart
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62935

Missing Authorization vulnerability in StackWC Open Close WooCommerce Store woc-open-close allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Close WooCommerce Store: from n/a through <= 5.0.0.

PUBLISHED
Vendor
StackWC
Product
Open Close WooCommerce Store
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62934

Cross-Site Request Forgery (CSRF) vulnerability in Mejar WP Business Hours wp-business-hours allows Stored XSS.This issue affects WP Business Hours: from n/a through <= 1.4.

PUBLISHED
Vendor
Mejar
Product
WP Business Hours
Provider severity
HIGH
Conflicts
0

CVE-2025-62933

Cross-Site Request Forgery (CSRF) vulnerability in Prakash Awesome Testimonials awesome-testimonials allows Stored XSS.This issue affects Awesome Testimonials: from n/a through <= 2.2.1.

PUBLISHED
Vendor
Prakash
Product
Awesome Testimonials
Provider severity
HIGH
Conflicts
0

CVE-2025-62932

Missing Authorization vulnerability in wprio Table Block by RioVizual riovizual allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Table Block by RioVizual: from n/a through <= 3.0.0.

PUBLISHED
Vendor
wprio
Product
Table Block by RioVizual
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62931

Missing Authorization vulnerability in microsoftstart MSN Partner Hub microsoft-start allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MSN Partner Hub: from n/a through <= 2.9.

PUBLISHED
Vendor
microsoftstart
Product
MSN Partner Hub
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62930

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows DOM-Based XSS.This issue affects MapSVG: from n/a through <= 8.7.22.

PUBLISHED
Vendor
RomanCode
Product
MapSVG
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6293

A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /contact_manager.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Hostel Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-62929

Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15.

PUBLISHED
Vendor
PickPlugins
Product
Testimonial Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62928

Missing Authorization vulnerability in Joby Joseph SEO Meta Description Updater seo-meta-description-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Meta Description Updater: from n/a through <= 1.2.0.

PUBLISHED
Vendor
Joby Joseph
Product
SEO Meta Description Updater
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62927

Missing Authorization vulnerability in Nelio Software Nelio Content nelio-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio Content: from n/a through <= 4.0.5.

PUBLISHED
Vendor
Nelio Software
Product
Nelio Content
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62926

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool [Show Current Template Info] current-template-name allows Stored XSS.This issue affects TempTool [Show Current Template Info]: from n/a through <= 1.3.1.

PUBLISHED
Vendor
HappyDevs
Product
TempTool [Show Current Template Info]
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62925

Missing Authorization vulnerability in Conversios Conversios.io enhanced-e-commerce-for-woocommerce-store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conversios.io: from n/a through <= 7.2.13.

PUBLISHED
Vendor
Conversios
Product
Conversios.io
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62924

Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17.

PUBLISHED
Vendor
PickPlugins
Product
Post Grid and Gutenberg Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62923

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio Marquee Addons for Elementor marquee-addons-for-elementor allows DOM-Based XSS.This issue affects Marquee Addons for Elementor: from n/a through <= 3.8.2.

PUBLISHED
Vendor
Debuggers Studio
Product
Marquee Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62922

Missing Authorization vulnerability in Shambhu Patnaik Export Categories export-categories allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export Categories: from n/a through <= 1.0.

PUBLISHED
Vendor
Shambhu Patnaik
Product
Export Categories
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62921

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagup Bulk Auto Image Title Attribute bulk-image-title-attribute allows DOM-Based XSS.This issue affects Bulk Auto Image Title Attribute: from n/a through <= 2.0.1.

PUBLISHED
Vendor
Pagup
Product
Bulk Auto Image Title Attribute
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62920

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webnique USERCENTRICS CMP usercentrics-consent-management-platform allows Stored XSS.This issue affects USERCENTRICS CMP: from n/a through <= 1.0.9.

PUBLISHED
Vendor
webnique
Product
USERCENTRICS CMP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6292

A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-825
Provider severity
HIGH
Conflicts
2

CVE-2025-62919

Missing Authorization vulnerability in themeshopy TS Demo Importer ts-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Demo Importer: from n/a through <= 0.1.3.

PUBLISHED
Vendor
themeshopy
Product
TS Demo Importer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62918

Missing Authorization vulnerability in ignitionwp IgnitionDeck ignitiondeck allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IgnitionDeck: from n/a through <= 2.0.15.

PUBLISHED
Vendor
ignitionwp
Product
IgnitionDeck
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62917

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jamel.Z Tooltipy bluet-keywords-tooltip-generator allows Stored XSS.This issue affects Tooltipy: from n/a through <= 5.5.9.

PUBLISHED
Vendor
Jamel.Z
Product
Tooltipy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62916

Missing Authorization vulnerability in Travon WP Flights & Hotels Booking WP Plugin adiaha-hotel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flights & Hotels Booking WP Plugin: from n/a through <= 3.1.

PUBLISHED
Vendor
Travon WP
Product
Flights & Hotels Booking WP Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62915

Missing Authorization vulnerability in clicksend SMS Contact Form 7 Notifications by ClickSend clicksend-contactform7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Contact Form 7 Notifications by ClickSend: from n/a through <= 1.4.0.

PUBLISHED
Vendor
clicksend
Product
SMS Contact Form 7 Notifications by ClickSend
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62914

Missing Authorization vulnerability in anibalwainstein Effect Maker effect-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Effect Maker: from n/a through <= 1.2.1.

PUBLISHED
Vendor
anibalwainstein
Product
Effect Maker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62913

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpopal Opal Service opal-service allows Stored XSS.This issue affects Opal Service: from n/a through <= 1.9.1.

PUBLISHED
Vendor
wpopal
Product
Opal Service
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62912

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.1.

PUBLISHED
Vendor
SiteGround
Product
SiteGround Email Marketing
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62911

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Content Rock Convert rock-convert allows Stored XSS.This issue affects Rock Convert: from n/a through <= 3.0.1.

PUBLISHED
Vendor
Rock Content
Product
Rock Convert
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62910

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in deshine Video Gallery by Huzzaz huzzaz-video-gallery allows Stored XSS.This issue affects Video Gallery by Huzzaz: from n/a through <= 10.5.

PUBLISHED
Vendor
deshine
Product
Video Gallery by Huzzaz
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6291

A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-825
Provider severity
HIGH
Conflicts
2

CVE-2025-62909

Missing Authorization vulnerability in mrityunjay Smart WeTransfer smart-wetransfer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WeTransfer: from n/a through <= 1.3.

PUBLISHED
Vendor
mrityunjay
Product
Smart WeTransfer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62907

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attachment: from n/a through <= 3.4.6.

PUBLISHED
Vendor
aviplugins.com
Product
Custom Post Type Attachment
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62906

Missing Authorization vulnerability in epiphanyit321 Referral Link Tracker referral-link-tracker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Referral Link Tracker: from n/a through <= 1.1.4.

PUBLISHED
Vendor
epiphanyit321
Product
Referral Link Tracker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62905

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Query Posts query-posts allows Stored XSS.This issue affects Query Posts: from n/a through <= 0.3.2.

PUBLISHED
Vendor
Justin Tadlock
Product
Query Posts
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62904

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Huson WP Geo wp-geo allows Stored XSS.This issue affects WP Geo: from n/a through <= 3.5.1.

PUBLISHED
Vendor
Ben Huson
Product
WP Geo
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62903

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPClever WPC Smart Messages for WooCommerce wpc-smart-messages allows Stored XSS.This issue affects WPC Smart Messages for WooCommerce: from n/a through <= 4.2.8.

PUBLISHED
Vendor
WPClever
Product
WPC Smart Messages for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62902

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk WP Popup Builder wp-popup-builder allows Retrieve Embedded Sensitive Data.This issue affects WP Popup Builder: from n/a through <= 1.3.8.

PUBLISHED
Vendor
ThemeHunk
Product
WP Popup Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62901

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten WP Microdata wp-microdata allows Stored XSS.This issue affects WP Microdata: from n/a through <= 1.0.

PUBLISHED
Vendor
tormorten
Product
WP Microdata
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62900

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WeblineIndia Popular Posts by Webline popular-posts-by-webline allows Stored XSS.This issue affects Popular Posts by Webline: from n/a through <= 1.1.1.

PUBLISHED
Vendor
WeblineIndia
Product
Popular Posts by Webline
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6290

The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bracket' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
blakelong
Product
Tournament Bracket Generator
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62899

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in THRIVE - Web Design Gold Coast Photospace Responsive photospace-responsive allows Stored XSS.This issue affects Photospace Responsive: from n/a through <= 2.2.0.

PUBLISHED
Vendor
THRIVE - Web Design Gold Coast
Product
Photospace Responsive
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62898

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maarten Links shortcode links-shortcode allows Stored XSS.This issue affects Links shortcode: from n/a through <= 1.8.3.

PUBLISHED
Vendor
Maarten
Product
Links shortcode
Provider severity
MEDIUM
Conflicts
0