Aggregator
CVE-2025-27268 | enituretechnology Small Package Quotes Plugin up to 5.2.18 on WordPress sql injection
1 year 3 months ago
A vulnerability was found in enituretechnology Small Package Quotes Plugin up to 5.2.18 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2025-27268. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-27094 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition expected behavior violation
1 year 3 months ago
A vulnerability was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to expected behavior violation.
This vulnerability is known as CVE-2025-27094. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-23505 | Pit Login Welcome Plugin up to 1.1.5 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in Pit Login Welcome Plugin up to 1.1.5 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-23505. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-27099 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition cross site scripting
1 year 3 months ago
A vulnerability was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition and classified as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting.
The identification of this vulnerability is CVE-2025-27099. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-26989 | softdiscover Zigaform Plugin up to 7.4.2 on WordPress cross site scripting
1 year 3 months ago
A vulnerability has been found in softdiscover Zigaform Plugin up to 7.4.2 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-26989. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23881 | LJ Custom Menu Links Plugin up to 2.5 on WordPress cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in LJ Custom Menu Links Plugin up to 2.5 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-23881. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-23555 | Ui Slider Filter by Price Plugin up to 1.1 on WordPress cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Ui Slider Filter by Price Plugin up to 1.1 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-23555. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-23553 | David Cramer Userbase Access Control Plugin up to 1.0 on WordPress cross site scripting
1 year 3 months ago
A vulnerability classified as problematic was found in David Cramer Userbase Access Control Plugin up to 1.0 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-23553. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-55532 | Apache Ranger up to 2.5.0 csv injection
1 year 3 months ago
A vulnerability classified as problematic has been found in Apache Ranger up to 2.5.0. Affected is an unknown function. The manipulation leads to csv injection.
This vulnerability is traded as CVE-2024-55532. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-23518 | GoogleMapper Plugin up to 2.0.3 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in GoogleMapper Plugin up to 2.0.3 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-23518. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-26984 | Cozy Vision SMS Alert Order Notifications Plugin up to 3.7.8 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in Cozy Vision SMS Alert Order Notifications Plugin up to 3.7.8 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-26984. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23556 | Push Envoy Notifications Plugin up to 1.0.0 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in Push Envoy Notifications Plugin up to 1.0.0 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-23556. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-26994 | softdiscover Zigaform Plugin up to 7.4.2 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in softdiscover Zigaform Plugin up to 7.4.2 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-26994. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24023 | dpgaspar Flask-AppBuilder up to 4.5.2 observable response discrepancy
1 year 3 months ago
A vulnerability has been found in dpgaspar Flask-AppBuilder up to 4.5.2 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to observable response discrepancy.
This vulnerability is known as CVE-2025-24023. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27271 | DB Tables Import Export Plugin up to 1.0.1 on WordPress cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in DB Tables Import Export Plugin up to 1.0.1 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-27271. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23517 | Google Map on Post Page Plugin up to 1.1 on WordPress cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in Google Map on Post Page Plugin up to 1.1 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-23517. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-27269 | .htaccess Login block Plugin up to 0.9a on WordPress cross site scripting
1 year 3 months ago
A vulnerability classified as problematic was found in .htaccess Login block Plugin up to 0.9a on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-27269. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23493 | Google Transliteration Plugin up to 1.7.2 on WordPress cross site scripting
1 year 3 months ago
A vulnerability classified as problematic has been found in Google Transliteration Plugin up to 1.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-23493. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-26967 | Stiofan Events Calendar for GeoDirectory Plugin up to 2.3.14 on WordPress deserialization
1 year 3 months ago
A vulnerability was found in Stiofan Events Calendar for GeoDirectory Plugin up to 2.3.14 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2025-26967. The attack may be launched remotely. There is no exploit available.
vuldb.com