CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2024-13462

    Last Modified: 15 Apr 2026

    The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2024-12339

    Last Modified: 15 Apr 2026

    The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' parameter in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 19 Feb 2025
    6.4
    Medium

    CVE-2024-13660

    Last Modified: 15 Apr 2026

    The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fshow' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2024-12069

    Last Modified: 15 Apr 2026

    The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can successfully trick a user into performing an action, such as clicking on a specially crafted link.

    Published: 19 Feb 2025
    6.4
    Medium

    CVE-2024-13674

    Last Modified: 15 Apr 2026

    The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cwp_social_share' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    4.3
    Medium

    CVE-2024-13854

    Last Modified: 8 Apr 2026

    The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.1 via the naedu_elementor_template shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract information from posts that are not public, including drafts, password protected, and restricted posts. This applies to posts created with Elementor only.

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2024-13711

    Last Modified: 8 Apr 2026

    The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 19 Feb 2025
    6.4
    Medium

    CVE-2024-12522

    Last Modified: 15 Apr 2026

    The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yayforms' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    5.3
    Medium

    CVE-2024-13719

    Last Modified: 8 Apr 2026

    The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which can contain PII of users.

    Published: 19 Feb 2025
    6.4
    Medium

    CVE-2024-13390

    Last Modified: 15 Apr 2026

    The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adfo_list' shortcode in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    4.9
    Medium

    CVE-2024-13712

    Last Modified: 8 Apr 2026

    The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 19 Feb 2025
    6.4
    Medium

    CVE-2024-13589

    Last Modified: 15 Apr 2026

    The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    6.5
    Medium

    CVE-2025-0865

    Last Modified: 19 Feb 2025

    The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or incorrect nonce validation on the wp_mcm_handle_action_settings() function. This makes it possible for unauthenticated attackers to alter plugin settings, such as the taxonomy used for media, the base slug for media categories, and the default media category via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 19 Feb 2025
    6.4
    Medium

    CVE-2024-13663

    Last Modified: 15 Apr 2026

    The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    5.1
    Medium

    CVE-2025-0633

    Last Modified: 15 Apr 2026

    Heap-based Buffer Overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows attacker to read out of bound memory

    Published: 19 Feb 2025
    5.4
    Medium

    CVE-2025-24841

    Last Modified: 15 Apr 2026

    Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may be executed on a logged-in user's web browser.

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2025-25054

    Last Modified: 15 Apr 2026

    Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while logged in to the affected product, an arbitrary script may be executed on the web browser of the user.

    Published: 19 Feb 2025
    5.4
    Medium

    CVE-2025-22888

    Last Modified: 15 Apr 2026

    Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be executed on a logged-in user's web browser.

    Published: 19 Feb 2025
    6.4
    Medium

    CVE-2024-13799

    Last Modified: 15 Apr 2026

    The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    6.4
    Medium

    CVE-2025-1065

    Last Modified: 22 Apr 2026

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2025-1441

    Last Modified: 22 Apr 2026

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 19 Feb 2025
    4.3
    Medium

    CVE-2025-22622

    Last Modified: 15 Apr 2026

    Age Verification for your checkout page. Verify your customer's identity 1.20.0 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/class-wc-integration-agechecker-integration.php.

    Published: 19 Feb 2025
    6.4
    Medium

    CVE-2024-13443

    Last Modified: 15 Apr 2026

    The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    7.2
    High

    CVE-2024-11582

    Last Modified: 15 Apr 2026

    The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2025
    3.5
    Low

    CVE-2024-12173

    Last Modified: 15 May 2025

    The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 19 Feb 2025
    6.9
    Medium

    CVE-2025-1448

    Last Modified: 15 Apr 2026

    A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This issue affects some unknown processing of the file 9-12ping.php. The manipulation of the argument retry leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Feb 2025
    5.3
    Medium

    CVE-2025-1447

    Last Modified: 15 Apr 2026

    A vulnerability was found in kasuganosoras Pigeon 1.0.177. It has been declared as critical. This vulnerability affects unknown code of the file /pigeon/imgproxy/index.php. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. Upgrading to version 1.0.181 is able to address this issue. The patch is identified as 84cea5fe73141689da2e7ec8676d47435bd6423e. It is recommended to upgrade the affected component.

    Published: 19 Feb 2025
    7.1
    High

    CVE-2024-57261

    Last Modified: 15 Apr 2026

    In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-57258.

    Published: 19 Feb 2025
    8.8
    High

    CVE-2023-46272

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute arbitrary code via the implementation of the ah_auth service

    Published: 19 Feb 2025
    9.1
    Critical

    CVE-2020-35546

    Last Modified: 15 Apr 2026

    Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2020-13481

    Last Modified: 15 Apr 2026

    Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other sensitive information.

    Published: 19 Feb 2025
    8.1
    High

    CVE-2020-10095

    Last Modified: 15 Apr 2026

    Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.

    Published: 19 Feb 2025
    5.5
    Medium

    CVE-2025-25946

    Last Modified: 9 Jun 2025

    An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file.

    Published: 19 Feb 2025
    6.5
    Medium

    CVE-2025-25945

    Last Modified: 13 May 2025

    An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.

    Published: 19 Feb 2025
    7.8
    High

    CVE-2025-25943

    Last Modified: 13 May 2025

    Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.

    Published: 19 Feb 2025
    7.1
    High

    CVE-2024-57262

    Last Modified: 15 Apr 2026

    In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite, a related issue to CVE-2024-57256.

    Published: 19 Feb 2025
    6.5
    Medium

    CVE-2025-25942

    Last Modified: 13 May 2025

    An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.

    Published: 19 Feb 2025
    7.3
    High

    CVE-2025-25944

    Last Modified: 13 May 2025

    Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.

    Published: 19 Feb 2025
    5.5
    Medium

    CVE-2025-25947

    Last Modified: 13 May 2025

    An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.

    Published: 19 Feb 2025
    7.5
    High

    CVE-2023-51301

    Last Modified: 4 Nov 2025

    A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 19 Feb 2025
    9.8
    Critical

    CVE-2023-46271

    Last Modified: 15 Apr 2026

    Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default.

    Published: 19 Feb 2025
    7.5
    High

    CVE-2023-51293

    Last Modified: 20 May 2025

    A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2023-51299

    Last Modified: 4 Nov 2025

    PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

    Published: 19 Feb 2025
    6.5
    Medium

    CVE-2023-51297

    Last Modified: 22 Apr 2025

    A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 19 Feb 2025
    4.7
    Medium

    CVE-2023-51298

    Last Modified: 22 Apr 2025

    PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

    Published: 19 Feb 2025
    8.8
    High

    CVE-2023-51302

    Last Modified: 23 Apr 2025

    PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2023-51296

    Last Modified: 4 Nov 2025

    PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary code

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2023-51300

    Last Modified: 4 Nov 2025

    PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.

    Published: 19 Feb 2025
    6.1
    Medium

    CVE-2023-51303

    Last Modified: 4 Nov 2025

    PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

    Published: 19 Feb 2025
    5.4
    Medium

    CVE-2023-51305

    Last Modified: 15 Apr 2026

    PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.

    Published: 19 Feb 2025