CVE Feed

    Dashboard / CVE

    8.3
    High

    CVE-2025-26530

    Last Modified: 11 Aug 2025

    The question bank filter required additional sanitizing to prevent a reflected XSS risk.

    Published: 24 Feb 2025
    8.3
    High

    CVE-2025-26529

    Last Modified: 8 Aug 2025

    Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

    Published: 24 Feb 2025
    3.4
    Low

    CVE-2025-26528

    Last Modified: 8 Aug 2025

    The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-26527

    Last Modified: 8 Aug 2025

    Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-26526

    Last Modified: 8 Aug 2025

    Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.

    Published: 24 Feb 2025
    8.6
    High

    CVE-2025-26525

    Last Modified: 8 Aug 2025

    Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).

    Published: 24 Feb 2025
    9.4
    Critical

    CVE-2025-27133

    Last Modified: 24 Feb 2025

    WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA application prior to version 3.2.15 at the `adicionar_tipo_exame.php` endpoint. This vulnerability allows an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. Version 3.2.15 contains a patch for the issue.

    Published: 24 Feb 2025
    6.9
    Medium

    CVE-2025-27112

    Last Modified: 27 Feb 2025

    Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subsonic API endpoints, a flaw in the authentication check process allows an attacker to specify any arbitrary username that does not exist on the system, along with a salted hash of an empty password. Under these conditions, Navidrome treats the request as authenticated, granting access to various Subsonic endpoints without requiring valid credentials. An attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in Navidrome, such as user playlists. However, any attempt to modify data fails with a "permission denied" error due to insufficient permissions, limiting the impact to unauthorized viewing of information. Version 0.54.5 contains a patch for this issue.

    Published: 24 Feb 2025
    8.4
    High

    CVE-2025-22495

    Last Modified: 15 Apr 2026

    An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result in an authenticated high privileged user having the ability to execute arbitrary commands. The vulnerability has been resolved in the version 3.0.4. Note - Network-M2 has been declared end-of-life in early 2024 and Network-M3 has been released as a fit-and-functional replacement.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27357

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Musa AVCI Önceki Yazı Link onceki-yazi-linki allows Cross Site Request Forgery.This issue affects Önceki Yazı Link: from n/a through <= 1.3.

    Published: 24 Feb 2025
    5.4
    Medium

    CVE-2025-27356

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Hardik Sticky Header On Scroll sticky-header-on-scroll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Header On Scroll: from n/a through <= 1.0.

    Published: 24 Feb 2025
    7.1
    High

    CVE-2025-27355

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nicolas GRILLET Woocommerce – Loi Hamon loi-hamon allows Stored XSS.This issue affects Woocommerce – Loi Hamon: from n/a through <= 1.1.0.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27353

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Bob Namaste! LMS namaste-lms allows Cross Site Request Forgery.This issue affects Namaste! LMS: from n/a through <= 2.6.5.

    Published: 24 Feb 2025
    7.1
    High

    CVE-2025-27352

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wumii team 无觅相关文章插件 wumii-related-posts allows Stored XSS.This issue affects 无觅相关文章插件: from n/a through <= 1.0.5.7.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27351

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpertBusinessSearch Local Search SEO Contact Page local-search-seo-contact-page allows Stored XSS.This issue affects Local Search SEO Contact Page: from n/a through <= 4.0.1.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27349

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts nurelm-get-posts allows Stored XSS.This issue affects Get Posts: from n/a through <= 0.6.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27348

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel WP Social SEO Booster – Knowledge Graph Social Signals SEO wp-social-seo-booster allows Stored XSS.This issue affects WP Social SEO Booster – Knowledge Graph Social Signals SEO: from n/a through <= 1.2.0.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27347

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techmix Direct Checkout Button for WooCommerce woo-direct-checkout-button allows Stored XSS.This issue affects Direct Checkout Button for WooCommerce: from n/a through <= 1.0.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27344

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in filipstepanov Phee's LinkPreview linkpreview allows Cross Site Request Forgery.This issue affects Phee's LinkPreview: from n/a through <= 1.6.7.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27342

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in josesan WooCommerce Recargo de Equivalencia woo-recargo-de-equivalencia allows Cross Site Request Forgery.This issue affects WooCommerce Recargo de Equivalencia: from n/a through <= 1.6.24.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27341

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in afzal_du Reactive Mortgage Calculator reactive-mortgage-calculator allows Stored XSS.This issue affects Reactive Mortgage Calculator: from n/a through <= 1.1.

    Published: 24 Feb 2025
    5.4
    Medium

    CVE-2025-27340

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site Request Forgery.This issue affects F12-Profiler: from n/a through <= 1.3.9.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27339

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength minimum-password-strength allows Cross Site Request Forgery.This issue affects Minimum Password Strength: from n/a through <= 1.2.0.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27336

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Alex Prokopenko / JustCoded Just Variables just-wp-variables allows Cross Site Request Forgery.This issue affects Just Variables: from n/a through <= 1.2.3.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27335

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Free plug in by SEO Roma Auto Tag Links auto-tag-links allows Cross Site Request Forgery.This issue affects Auto Tag Links: from n/a through <= 1.0.13.

    Published: 24 Feb 2025
    7.1
    High

    CVE-2025-27332

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in gmnazmul Smart Maintenance & Countdown smart-maintenance-countdown allows Stored XSS.This issue affects Smart Maintenance & Countdown: from n/a through <= 1.2.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27331

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sébastien Dumont WooCommerce Display Products by Tags woocommerce-display-products-by-tags allows DOM-Based XSS.This issue affects WooCommerce Display Products by Tags: from n/a through <= 1.0.0.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27330

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PlayerJS PlayerJS playerjs allows DOM-Based XSS.This issue affects PlayerJS: from n/a through <= 2.23.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27329

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup inlinkz-scripter allows DOM-Based XSS.This issue affects EZ InLinkz linkup: from n/a through <= 0.18.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27328

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in queeez WP-PostRatings Cheater wp-postratings-cheater allows Cross Site Request Forgery.This issue affects WP-PostRatings Cheater: from n/a through <= 1.5.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27327

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Winlin Live Streaming Video Player – by SRS Player srs-player allows DOM-Based XSS.This issue affects Live Streaming Video Player – by SRS Player: from n/a through <= 1.0.18.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-26883

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in bPlugins Animated Text Block animated-text-block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animated Text Block: from n/a through <= 1.0.7.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27325

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruce Video.js HLS Player videojs-hls-player allows DOM-Based XSS.This issue affects Video.js HLS Player: from n/a through <= 1.0.2.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27323

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jon Bishop WP About Author wp-about-author allows DOM-Based XSS.This issue affects WP About Author: from n/a through <= 1.5.

    Published: 24 Feb 2025
    7.1
    High

    CVE-2025-27321

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer: from n/a through <= 2.3.0.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27320

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pankaj Mondal Profile Widget Ninja profile-widget-ninja allows DOM-Based XSS.This issue affects Profile Widget Ninja: from n/a through <= 4.3.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27318

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ixiter Simple Google Sitemap simple-google-sitemap allows Cross Site Request Forgery.This issue affects Simple Google Sitemap: from n/a through <= 1.6.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27317

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in IT-RAYS RAYS Grid rays-grid allows Cross Site Request Forgery.This issue affects RAYS Grid: from n/a through <= 1.3.1.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27316

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in hosting.io JPG, PNG Compression and Optimization wp-image-compression allows Cross Site Request Forgery.This issue affects JPG, PNG Compression and Optimization: from n/a through <= 1.7.35.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27315

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wptom All-In-One Cufon all-in-one-cufon allows Cross Site Request Forgery.This issue affects All-In-One Cufon: from n/a through <= 1.3.0.

    Published: 24 Feb 2025
    8.5
    High

    CVE-2025-27312

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jenst WP Sitemap wp-sitemap allows SQL Injection.This issue affects WP Sitemap: from n/a through <= 1.0.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27311

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in luk3thomas Bulk Content Creator bulk-content-creator allows Cross Site Request Forgery.This issue affects Bulk Content Creator: from n/a through <= 1.2.1.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27307

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama quotes-llama allows Reflected XSS.This issue affects Quotes llama: from n/a through <= 3.0.1.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27306

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pathomation Pathomation pathomation allows Stored XSS.This issue affects Pathomation: from n/a through <= 2.5.1.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27305

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Achal Jain Table of Contents Block table-of-contents allows Stored XSS.This issue affects Table of Contents Block: from n/a through <= 1.0.2.

    Published: 24 Feb 2025
    5.9
    Medium

    CVE-2025-27304

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating with font Awesome contact-form-7-star-rating-with-font-awersome allows Stored XSS.This issue affects Contact Form 7 Star Rating with font Awesome: from n/a through <= 1.3.

    Published: 24 Feb 2025
    5.9
    Medium

    CVE-2025-27303

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating contact-form-7-star-rating allows Stored XSS.This issue affects Contact Form 7 Star Rating: from n/a through <= 1.10.

    Published: 24 Feb 2025
    7.2
    High

    CVE-2025-27301

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager nhrrob-options-table-manager allows Object Injection.This issue affects NHR Options Table Manager: from n/a through <= 1.1.2.

    Published: 24 Feb 2025
    7.2
    High

    CVE-2025-27300

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affects ADFO: from n/a through <= 1.9.1.

    Published: 24 Feb 2025
    8.3
    High

    CVE-2025-27298

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in cmstactics WP Video Posts wp-video-posts allows OS Command Injection.This issue affects WP Video Posts: from n/a through <= 3.5.1.

    Published: 24 Feb 2025