CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2025-48324

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in khashabawy tli.tl auto Twitter poster tlitl-auto-twitter-poster allows Stored XSS.This issue affects tli.tl auto Twitter poster: from n/a through <= 3.4.

    Published: 28 Aug 2025
    5.9
    Medium

    CVE-2025-48323

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Abunaser Khan Advance Food Menu advance-food-menu allows Stored XSS.This issue affects Advance Food Menu: from n/a through <= 1.0.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-48322

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Finn Dohrn Statify Widget statify-widget allows Stored XSS.This issue affects Statify Widget: from n/a through <= 1.4.6.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-48321

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget ultimate-twitter-profile-widget allows Stored XSS.This issue affects Ultimate twitter profile widget: from n/a through <= 1.0.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-48320

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in cuckoohello 百度分享按钮 baidushare-wp allows Stored XSS.This issue affects 百度分享按钮: from n/a through <= 1.0.6.

    Published: 28 Aug 2025
    5.9
    Medium

    CVE-2025-48319

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gslauraspeck Mesa Mesa Reservation Widget mesa-mesa-reservation-widget allows Stored XSS.This issue affects Mesa Mesa Reservation Widget: from n/a through <= 1.0.0.

    Published: 28 Aug 2025
    4.3
    Medium

    CVE-2025-48318

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in shen2 多说社会化评论框 duoshuo allows Cross Site Request Forgery.This issue affects 多说社会化评论框: from n/a through <= 1.2.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-48316

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ItayXD Responsive Mobile-Friendly Tooltip responsive-mobile-friendly-tooltip allows Stored XSS.This issue affects Responsive Mobile-Friendly Tooltip: from n/a through <= 1.6.6.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-48315

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stanton119 WordPress HTML custom-html-bodyhead allows Stored XSS.This issue affects WordPress HTML: from n/a through <= 0.51.

    Published: 28 Aug 2025
    5.9
    Medium

    CVE-2025-48314

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salubrio Add Code To Head add-code-to-head allows Stored XSS.This issue affects Add Code To Head: from n/a through <= 1.17.

    Published: 28 Aug 2025
    5.9
    Medium

    CVE-2025-48313

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kevin heath Tripadvisor Shortcode tripadvisor-shortcode allows Stored XSS.This issue affects Tripadvisor Shortcode: from n/a through <= 2.2.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-48312

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 文派翻译(WP Chinese Translation) WPAvatar wpavatar allows Stored XSS.This issue affects WPAvatar: from n/a through <= 1.9.4.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-48311

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in OffClicks Invisible Optin invisible-optin allows Stored XSS.This issue affects Invisible Optin: from n/a through <= 1.0.

    Published: 28 Aug 2025
    4.3
    Medium

    CVE-2025-48310

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wptableeditor Table Editor wp-table-editor allows Cross Site Request Forgery.This issue affects Table Editor: from n/a through <= 1.6.4.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-48309

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in web-able BetPress betpress allows Stored XSS.This issue affects BetPress: from n/a through <= 1.0.1 Lite.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-48308

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module newsletter-subscription-widget-for-sendblaster allows Stored XSS.This issue affects Newsletter subscription optin module: from n/a through <= 1.2.9.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-48307

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao SEO For Images seo-for-images allows Stored XSS.This issue affects SEO For Images: from n/a through <= 1.0.0.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-48306

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in developers savyour Savyour Affiliate Partner savyour-affiliate-partner allows Stored XSS.This issue affects Savyour Affiliate Partner: from n/a through <= 2.1.4.

    Published: 28 Aug 2025
    5.9
    Medium

    CVE-2025-48305

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikingjs Goal Tracker for Patreon goal-tracker-for-patreon allows Stored XSS.This issue affects Goal Tracker for Patreon: from n/a through <= 0.4.6.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-48304

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin gn-xml-sitemap allows Stored XSS.This issue affects Google XML News Sitemap plugin: from n/a through <= 0.02.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-48110

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View link-view allows Stored XSS.This issue affects Link View: from n/a through <= 0.8.0.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-48109

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Xavier Media XM-Backup xm-backup allows Stored XSS.This issue affects XM-Backup: from n/a through <= 0.9.1.

    Published: 28 Aug 2025
    9.1
    Critical

    CVE-2025-48100

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbuystoreintegrator allows Remote Code Inclusion.This issue affects bidorbuy Store Integrator: from n/a through <= 2.12.0.

    Published: 28 Aug 2025
    9.3
    Critical

    CVE-2025-39496

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Product Filter Pro allows SQL Injection.This issue affects WooBeWoo Product Filter Pro: from n/a before 2.9.6.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-9376

    Last Modified: 22 Apr 2026

    The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions up to, and including, 11.58. This makes it possible for unauthenticated attackers to bypass blocklists, rate limits, and other plugin functionality.

    Published: 28 Aug 2025
    5.1
    Medium

    CVE-2025-55175

    Last Modified: 8 Sept 2025

    QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 28 Aug 2025
    5.3
    Medium

    CVE-2025-54544

    Last Modified: 8 Sept 2025

    QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 28 Aug 2025
    5.3
    Medium

    CVE-2025-54543

    Last Modified: 8 Sept 2025

    QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 28 Aug 2025
    6.9
    Medium

    CVE-2025-54542

    Last Modified: 8 Sept 2025

    QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 28 Aug 2025
    6.9
    Medium

    CVE-2025-54541

    Last Modified: 8 Sept 2025

    QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 28 Aug 2025
    5.1
    Medium

    CVE-2025-54540

    Last Modified: 8 Sept 2025

    QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 28 Aug 2025
    7.3
    High

    CVE-2025-48963

    Last Modified: 15 Apr 2026

    Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40296.

    Published: 28 Aug 2025
    Unknown

    CVE-2025-58333

    Last Modified: 29 Aug 2025

    Not used

    Published: 28 Aug 2025
    Unknown

    CVE-2025-58328

    Last Modified: 29 Aug 2025

    Not used

    Published: 28 Aug 2025
    Unknown

    CVE-2025-58329

    Last Modified: 29 Aug 2025

    Not used

    Published: 28 Aug 2025
    Unknown

    CVE-2025-58326

    Last Modified: 29 Aug 2025

    Not used

    Published: 28 Aug 2025
    Unknown

    CVE-2025-58327

    Last Modified: 29 Aug 2025

    Not used

    Published: 28 Aug 2025
    Unknown

    CVE-2025-58330

    Last Modified: 29 Aug 2025

    Not used

    Published: 28 Aug 2025
    Unknown

    CVE-2025-58331

    Last Modified: 29 Aug 2025

    Not used

    Published: 28 Aug 2025
    Unknown

    CVE-2025-58332

    Last Modified: 29 Aug 2025

    Not used

    Published: 28 Aug 2025
    8.7
    High

    CVE-2025-58081

    Last Modified: 15 Apr 2026

    Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to view arbitrary files with root privileges.

    Published: 28 Aug 2025
    8.7
    High

    CVE-2025-58072

    Last Modified: 15 Apr 2026

    Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-54819

    Last Modified: 15 Apr 2026

    Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, legitimate files may be overwritten by a remote authenticated attacker.

    Published: 28 Aug 2025
    9.3
    Critical

    CVE-2025-54762

    Last Modified: 15 Apr 2026

    SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges.

    Published: 28 Aug 2025
    9.3
    Critical

    CVE-2025-53970

    Last Modified: 15 Apr 2026

    SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges.

    Published: 28 Aug 2025
    7.3
    High

    CVE-2025-53396

    Last Modified: 15 Apr 2026

    Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier), which may allow users who can log in to a client terminal to obtain root privileges.

    Published: 28 Aug 2025
    6.9
    Medium

    CVE-2025-52460

    Last Modified: 15 Apr 2026

    Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If exploited, uploaded files and SS1 configuration files may be accessed by a remote unauthenticated attacker.

    Published: 28 Aug 2025
    8.7
    High

    CVE-2025-46409

    Last Modified: 15 Apr 2026

    Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, a function that requires authentication may be accessed by a remote unauthenticated attacker.

    Published: 28 Aug 2025
    7.8
    High

    CVE-2025-58322

    Last Modified: 16 Oct 2025

    NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs due to improper privilege checks.

    Published: 28 Aug 2025
    6.4
    Medium

    CVE-2025-6255

    Last Modified: 22 Apr 2026

    The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Aug 2025