CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2021-26105

    Last Modified: 24 Jul 2025

    A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.

    Published: 24 Mar 2025
    6.5
    Medium

    CVE-2025-1558

    Last Modified: 25 Sept 2025

    Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30623

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry wA11y – The Web Accessibility Toolbox wa11y allows Stored XSS.This issue affects wA11y – The Web Accessibility Toolbox: from n/a through <= 1.0.3.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30621

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in kornelly Translator translator allows Stored XSS.This issue affects Translator: from n/a through <= 0.3.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30620

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in coderscom WP Odoo Form Integrator wp-odoo-form-integrator allows Stored XSS.This issue affects WP Odoo Form Integrator: from n/a through <= 1.1.0.

    Published: 24 Mar 2025
    5.4
    Medium

    CVE-2025-30619

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in SpeakPipe SpeakPipe speakpipe-voicemail-for-websites allows Cross Site Request Forgery.This issue affects SpeakPipe: from n/a through <= 0.2.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30617

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in takien Rewrite rewrite allows Cross Site Request Forgery.This issue affects Rewrite: from n/a through <= 0.2.1.

    Published: 24 Mar 2025
    9.6
    Critical

    CVE-2025-30615

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jacob Schwartz WP e-Commerce Style Email wp-e-commerce-style-email allows Code Injection.This issue affects WP e-Commerce Style Email: from n/a through <= 0.6.2.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30612

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in mandegarweb Replace Default Words replace-default-words allows Stored XSS.This issue affects Replace Default Words: from n/a through <= 1.3.

    Published: 24 Mar 2025
    6.5
    Medium

    CVE-2025-30610

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget wp-social-widget allows Stored XSS.This issue affects WP Social Widget: from n/a through <= 2.2.7.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-30609

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal AppExperts appexperts allows Retrieve Embedded Sensitive Data.This issue affects AppExperts: from n/a through <= 1.4.3.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30608

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Anthony WordPress SQL Backup wordpress-sql-backup allows Stored XSS.This issue affects WordPress SQL Backup: from n/a through <= 3.5.2.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30606

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Logan Carlile Easy Page Transition easy-page-transition allows Stored XSS.This issue affects Easy Page Transition: from n/a through <= 1.0.1.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30605

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ldwin79 sourceplay-navermap sourceplay-navermap allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects sourceplay-navermap: from n/a through <= 0.0.2.

    Published: 24 Mar 2025
    7.6
    High

    CVE-2025-30604

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jiangqie JiangQie Official Website Mini Program jiangqie-official-website-mini-program allows Blind SQL Injection.This issue affects JiangQie Official Website Mini Program: from n/a through <= 1.8.2.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30603

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in DEJAN CopyLink copy-link allows Stored XSS.This issue affects CopyLink: from n/a through <= 1.1.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30602

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alphasis Related Posts via Categories related-posts-via-categories allows Stored XSS.This issue affects Related Posts via Categories: from n/a through <= 2.1.2.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30601

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in flipdish Flipdish Ordering System flipdish-ordering-system allows Cross Site Request Forgery.This issue affects Flipdish Ordering System: from n/a through <= 1.5.2.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30600

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thiagogsrwp WP Hotjar wp-hotjar allows Stored XSS.This issue affects WP Hotjar: from n/a through <= 0.0.3.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30599

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp-maverick WP Parallax Content Slider wp-parallax-content-slider allows Stored XSS.This issue affects WP Parallax Content Slider: from n/a through <= 0.9.8.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30598

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Link OSS Upload oss-upload allows Cross Site Request Forgery.This issue affects OSS Upload: from n/a through <= 4.8.9.

    Published: 24 Mar 2025
    6.5
    Medium

    CVE-2025-30597

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iografica IG Shortcodes ig-shortcodes allows DOM-Based XSS.This issue affects IG Shortcodes: from n/a through <= 3.1.

    Published: 24 Mar 2025
    6.5
    Medium

    CVE-2025-30595

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tstafford include-file include-file allows Stored XSS.This issue affects include-file: from n/a through <= 1.

    Published: 24 Mar 2025
    6.5
    Medium

    CVE-2025-30593

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in samsk Include URL include-url allows Stored XSS.This issue affects Include URL: from n/a through <= 0.3.5.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-30592

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WesternDeal Advanced Dewplayer advanced-dewplayer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Dewplayer: from n/a through <= 1.6.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-30591

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in tuyennv Music Press Pro music-press-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Music Press Pro: from n/a through <= 1.4.6.

    Published: 24 Mar 2025
    8.5
    High

    CVE-2025-30590

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dourou Flickr set slideshows flickr-set-slideshows allows SQL Injection.This issue affects Flickr set slideshows: from n/a through <= 0.9.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30588

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ryan_xantoo Map Contact map-contact allows Stored XSS.This issue affects Map Contact: from n/a through <= 3.0.4.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30587

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in shawfactor LH OGP Meta lh-ogp-meta-tags allows Stored XSS.This issue affects LH OGP Meta: from n/a through <= 1.73.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30586

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in bbodine1 cTabs ctabs allows Stored XSS.This issue affects cTabs: from n/a through <= 1.3.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30585

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in marynixie Generate Post Thumbnails generate-post-thumbnails allows Cross Site Request Forgery.This issue affects Generate Post Thumbnails: from n/a through <= 0.8.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30584

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in alphaomegaplugins AlphaOmega Captcha & Anti-Spam Filter alphaomega-captcha-anti-spam allows Stored XSS.This issue affects AlphaOmega Captcha & Anti-Spam Filter: from n/a through <= 3.3.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30583

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ProRankTracker Pro Rank Tracker proranktracker allows Stored XSS.This issue affects Pro Rank Tracker: from n/a through <= 1.0.0.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-30581

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in PluginOps Top Bar ultimate-bar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Top Bar: from n/a through <= 3.3.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30578

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in hotvanrod AdSense Privacy Policy adsense-privacy-policy allows Stored XSS.This issue affects AdSense Privacy Policy: from n/a through <= 1.1.1.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30577

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in mendibass Browser Address Bar Color browser-address-bar-color allows Stored XSS.This issue affects Browser Address Bar Color: from n/a through <= 3.3.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30576

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Image Autosave hacklog-remote-image-autosave allows Cross Site Request Forgery.This issue affects Hacklog Remote Image Autosave: from n/a through <= 2.1.0.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30575

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arefly Login Redirect login-redirect allows Stored XSS.This issue affects Login Redirect: from n/a through <= 1.0.5.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30574

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jenst Mobile Navigation mobile-navigation allows Stored XSS.This issue affects Mobile Navigation: from n/a through <= 1.5.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30573

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mrdenny My Default Post Content my-default-post-content allows Stored XSS.This issue affects My Default Post Content: from n/a through <= 0.7.3.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30572

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Igor Yavych Simple Rating simple-rating allows Stored XSS.This issue affects Simple Rating: from n/a through <= 1.4.

    Published: 24 Mar 2025
    7.6
    High

    CVE-2025-30571

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in STEdb Corp. STEdb Forms stedb-forms allows SQL Injection.This issue affects STEdb Forms: from n/a through <= 1.0.4.

    Published: 24 Mar 2025
    7.6
    High

    CVE-2025-30570

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AliRezaMohammadi دکمه، شبکه اجتماعی خرید dokme allows SQL Injection.This issue affects دکمه، شبکه اجتماعی خرید: from n/a through <= 2.0.6.

    Published: 24 Mar 2025
    8.5
    High

    CVE-2025-30569

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jahertor WP Featured Entries wp-featured-entries allows SQL Injection.This issue affects WP Featured Entries: from n/a through <= 1.0.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30568

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in hitoy Super Static Cache super-static-cache allows Cross Site Request Forgery.This issue affects Super Static Cache: from n/a through <= 3.3.5.

    Published: 24 Mar 2025
    6.5
    Medium

    CVE-2025-30566

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aryan Themes Clink clink allows DOM-Based XSS.This issue affects Clink: from n/a through <= 1.2.2.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30565

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in karrikas banner-manager banner-manager allows Stored XSS.This issue affects banner-manager: from n/a through <= 16.04.19.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30564

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpwox Custom Script Integration custom-script-integration allows Stored XSS.This issue affects Custom Script Integration: from n/a through <= 2.1.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30561

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Henrique Mouta CAS Maestro cas-maestro allows Stored XSS.This issue affects CAS Maestro: from n/a through <= 1.1.3.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30560

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sana Ullah jQuery Dropdown Menu jquery-drop-down-menu-plugin allows Stored XSS.This issue affects jQuery Dropdown Menu: from n/a through <= 3.0.

    Published: 24 Mar 2025