CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2025-2233

    Last Modified: 26 Feb 2026

    Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Samsung SmartThings. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Hub Local API service, which listens on TCP port 8766 by default. The issue results from the lack of proper verification of a cryptographic signature. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25615.

    Published: 11 Mar 2025
    4.8
    Medium

    CVE-2025-2211

    Last Modified: 21 May 2025

    A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /sysDictDetail/add. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Mar 2025
    4.8
    Medium

    CVE-2025-2210

    Last Modified: 21 May 2025

    A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /sysJob/add. The manipulation of the argument name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Mar 2025
    7.7
    High

    CVE-2025-27792

    Last Modified: 15 Apr 2026

    Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request forgery (CSRF) were insufficient application-wide. The referrer header is checked, and if it is invalid, the server returns 403. However, the referrer header can be dropped from CSRF requests using `<meta name="referrer" content="never">`, effectively bypassing this protection. Version 5.1.1 contains a patch for the issue.

    Published: 11 Mar 2025
    7.3
    High

    CVE-2025-27101

    Last Modified: 15 Apr 2026

    Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, when copying any parent directory to a folder in the /temp/ directory, all files in that parent directory are copied, including files which the user should not have access to. All users of the application are impacted, as this is exploitable by any user to reveal all files in the opal filesystem. This also means that low-privilege users such as DataShield users can retrieve the files of other users. Version 5.1.1 contains a patch for the issue.

    Published: 11 Mar 2025
    4.8
    Medium

    CVE-2025-2209

    Last Modified: 21 May 2025

    A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unknown function of the file /sysDict/add. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Mar 2025
    8.8
    High

    CVE-2025-1707

    Last Modified: 21 Apr 2026

    The Review Schema plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.4 via post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28868

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe ziplist-recipe-plugin allows Cross Site Request Forgery.This issue affects ZipList Recipe: from n/a through <= 3.1.

    Published: 11 Mar 2025
    5.9
    Medium

    CVE-2025-28943

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mylo2h2s DP ALTerminator - Missing ALT manager dp-alterminator-missing-alt-manager allows Stored XSS.This issue affects DP ALTerminator - Missing ALT manager: from n/a through <= 1.0.2.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28941

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ohtan Spam Byebye spam-byebye allows Cross Site Request Forgery.This issue affects Spam Byebye: from n/a through <= 2.2.4.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28940

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in arkapravamajumder Back To Top backtotop allows Cross Site Request Forgery.This issue affects Back To Top: from n/a through <= 2.0.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28938

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Performance Pack: from n/a through <= 2.5.3.

    Published: 11 Mar 2025
    5.9
    Medium

    CVE-2025-28937

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Search lava-ajax-search allows Stored XSS.This issue affects Lava Ajax Search: from n/a through <= 1.1.9.

    Published: 11 Mar 2025
    5.9
    Medium

    CVE-2025-28936

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sakurapixel Lunar lunar-sell-photos-online allows Stored XSS.This issue affects Lunar: from n/a through <= 1.3.0.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28933

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in maxfoundry MaxA/B maxab allows Stored XSS.This issue affects MaxA/B: from n/a through <= 2.2.2.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28932

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in BCS Website Solutions Insert Code insert-code allows Stored XSS.This issue affects Insert Code: from n/a through <= 2.4.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28931

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in DevriX Hashtags wp-hashtags allows Stored XSS.This issue affects Hashtags: from n/a through <= 0.3.2.

    Published: 11 Mar 2025
    6.5
    Medium

    CVE-2025-28930

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rodolphe MOULIN List Mixcloud list-mixcloud allows Stored XSS.This issue affects List Mixcloud: from n/a through <= 1.4.

    Published: 11 Mar 2025
    6.5
    Medium

    CVE-2025-28929

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tabbed Login Widget tabbed-login allows Stored XSS.This issue affects Tabbed Login Widget: from n/a through <= 1.1.2.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28927

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in A. Chappard Display Template Name display-template-name allows Cross Site Request Forgery.This issue affects Display Template Name: from n/a through <= 1.7.1.

    Published: 11 Mar 2025
    5.9
    Medium

    CVE-2025-28926

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in popeating Post Read Time post-read-time allows Stored XSS.This issue affects Post Read Time: from n/a through <= 1.2.6.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28925

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Hieu Nguyen WATI Chat and Notification wati-chat-and-notification allows Stored XSS.This issue affects WATI Chat and Notification: from n/a through <= 1.1.2.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28923

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in philippe No Disposable Email no-disposable-email allows Stored XSS.This issue affects No Disposable Email: from n/a through <= 2.5.1.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28922

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Terence D. Go To Top go-to-top allows Stored XSS.This issue affects Go To Top: from n/a through <= 0.0.8.

    Published: 11 Mar 2025
    5.3
    Medium

    CVE-2025-28920

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Jogesh Responsive Google Map responsive-google-map allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Google Map: from n/a through <= 3.1.5.

    Published: 11 Mar 2025
    6.5
    Medium

    CVE-2025-28919

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shellbot Easy Image Display easy-image-display allows Stored XSS.This issue affects Easy Image Display: from n/a through <= 1.2.5.

    Published: 11 Mar 2025
    6.5
    Medium

    CVE-2025-28918

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones Featured Image Thumbnail Grid thumbnail-grid allows Stored XSS.This issue affects Featured Image Thumbnail Grid: from n/a through <= 6.8.

    Published: 11 Mar 2025
    9.1
    Critical

    CVE-2025-28915

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Server.This issue affects ThemeEgg ToolKit: from n/a through <= 1.2.9.

    Published: 11 Mar 2025
    5.9
    Medium

    CVE-2025-28914

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere wp-show-login-form allows Stored XSS.This issue affects wordpress login form to anywhere: from n/a through <= 0.2.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28913

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Aftab Ali Muni WP Add Active Class To Menu Item wp-add-active-class-to-menu-item allows Cross Site Request Forgery.This issue affects WP Add Active Class To Menu Item: from n/a through <= 1.0.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28912

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Muntasir Rahman Custom Dashboard Page custom-dashboard-page allows Cross Site Request Forgery.This issue affects Custom Dashboard Page: from n/a through <= 1.0.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28910

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ravinder Khurana WP Hide Admin Bar wp-hide-admin-bar allows Cross Site Request Forgery.This issue affects WP Hide Admin Bar: from n/a through <= 2.0.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28909

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in edwardw WP No-Bot Question wp-no-bot-question allows Cross Site Request Forgery.This issue affects WP No-Bot Question: from n/a through <= 0.1.7.

    Published: 11 Mar 2025
    5.9
    Medium

    CVE-2025-28908

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pipdig pipDisqus pipdisqus allows Stored XSS.This issue affects pipDisqus: from n/a through <= 1.6.

    Published: 11 Mar 2025
    5.9
    Medium

    CVE-2025-28907

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rahul Arora WP Last Modified wp-last-modified allows Stored XSS.This issue affects WP Last Modified: from n/a through <= 0.1.

    Published: 11 Mar 2025
    5.9
    Medium

    CVE-2025-28906

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thiago S.F. Skitter Slideshow wp-skitter-slideshow allows Stored XSS.This issue affects Skitter Slideshow: from n/a through <= 2.5.2.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28905

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chaser324 Featured Posts Grid featured-posts-grid allows Stored XSS.This issue affects Featured Posts Grid: from n/a through <= 1.7.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28902

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Benjamin Pick Contact Form 7 Select Box Editor Button contact-form-7-select-box-editor-button allows Cross Site Request Forgery.This issue affects Contact Form 7 Select Box Editor Button: from n/a through <= 0.6.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28901

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Naren Members page only for logged in users members-page-only-for-logged-in-users allows Stored XSS.This issue affects Members page only for logged in users: from n/a through <= 1.4.2.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28900

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in webgarb TabGarb Pro tabgarb allows Stored XSS.This issue affects TabGarb Pro: from n/a through <= 2.6.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28897

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Steveorevo Domain Theme domain-theme allows Stored XSS.This issue affects Domain Theme: from n/a through <= 1.3.

    Published: 11 Mar 2025
    4.7
    Medium

    CVE-2025-28896

    Last Modified: 23 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akshar Soft Solutions AS English Admin as-english-admin allows Phishing.This issue affects AS English Admin: from n/a through <= 1.0.0.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28895

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suman Biswas Custom top bar custom-top-bar allows Stored XSS.This issue affects Custom top bar: from n/a through <= 2.1.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28894

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in frucomerci List of Posts from each Category plugin for WordPress list-posts-by-category allows Stored XSS.This issue affects List of Posts from each Category plugin for WordPress: from n/a through <= 2.0.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28892

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in a2rocklobster FTP Sync ftp-sync allows Stored XSS.This issue affects FTP Sync: from n/a through <= 1.1.6.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28891

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in jazzigor price-calc price-calc allows Stored XSS.This issue affects price-calc: from n/a through <= 0.6.3.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28887

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Fastmover Plugins Last Updated Column plugins-last-updated-column allows Cross Site Request Forgery.This issue affects Plugins Last Updated Column: from n/a through <= 0.1.3.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28886

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in xjb REST API TO MiniProgram rest-api-to-miniprogram allows Cross Site Request Forgery.This issue affects REST API TO MiniProgram: from n/a through <= 5.1.2.

    Published: 11 Mar 2025
    4.3
    Medium

    CVE-2025-28884

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator wp-bulk-post-duplicator allows Cross Site Request Forgery.This issue affects WP Bulk Post Duplicator: from n/a through <= 1.2.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-28883

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Martin WP Compare Tables wp-compare-tables allows Stored XSS.This issue affects WP Compare Tables: from n/a through <= 1.0.5.

    Published: 11 Mar 2025