CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-23860

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in crea8xion Charity-thermometer charitydonation-thermometer allows Stored XSS.This issue affects Charity-thermometer: from n/a through <= 1.1.2.

    Published: 16 Jan 2025
    5.3
    Medium

    CVE-2025-23862

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in SzMake Contact Form 7 Anti Spambot contact-form-7-anti-spambot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form 7 Anti Spambot: from n/a through <= 1.0.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23861

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Zack Katz Debt Calculator debt-calculator allows Cross Site Request Forgery.This issue affects Debt Calculator: from n/a through <= 1.0.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23856

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Odyno Simple Vertical Timeline simple-vertical-timeline allows DOM-Based XSS.This issue affects Simple Vertical Timeline: from n/a through <= 0.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23848

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in dpowney Hotspots Analytics hotspots allows Stored XSS.This issue affects Hotspots Analytics: from n/a through <= 4.0.12.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23842

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nilesh Shiragave WordPress Gallery Plugin wordpress-gallery-plugin allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin: from n/a through <= 1.4.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23830

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jobair JB Horizontal Scroller News Ticker jb-horizontal-scroller-news-ticker allows DOM-Based XSS.This issue affects JB Horizontal Scroller News Ticker: from n/a through <= 1.0.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23841

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foo123 Top Flash Embed top-flash-embed allows Stored XSS.This issue affects Top Flash Embed: from n/a through <= 0.3.4.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23844

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jamsheer K Custom Widget Classes custom-widget-classes allows Cross Site Request Forgery.This issue affects Custom Widget Classes: from n/a through <= 1.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23831

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mobstac QR Code Generator qrcode-wprhe allows DOM-Based XSS.This issue affects QR Code Generator: from n/a through <= 1.2.6.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23828

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sindhi WordPress Data Guard wordpress-data-guards allows Stored XSS.This issue affects WordPress Data Guard: from n/a through <= 8.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23826

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pedjas Stop Comment Spam stop-comment-spam allows Stored XSS.This issue affects Stop Comment Spam: from n/a through <= 0.5.3.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23824

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexander Weleczka FontAwesome.io ShortCodes allows Stored XSS.This issue affects FontAwesome.io ShortCodes: from n/a through 1.0.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23833

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RaminMT Links/Problem Reporter report-broken-links allows DOM-Based XSS.This issue affects Links/Problem Reporter: from n/a through <= 2.6.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23823

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in jprintf CNZZ&51LA for WordPress cnzz51la-for-wordpress allows Cross Site Request Forgery.This issue affects CNZZ&51LA for WordPress: from n/a through <= 1.0.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23825

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Shortcode Buttons easy-shortcode-buttons allows Stored XSS.This issue affects Easy Shortcode Buttons: from n/a through <= 1.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23821

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in aleapp WP Cookies Alert wp-cookies-alert allows Cross Site Request Forgery.This issue affects WP Cookies Alert: from n/a through <= 1.1.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23832

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Matt Gibbs Admin Cleanup admin-cleanup allows Stored XSS.This issue affects Admin Cleanup: from n/a through <= 1.0.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23820

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in thapa.laxman Content Security Policy Pro content-security-policy-pro allows Cross Site Request Forgery.This issue affects Content Security Policy Pro: from n/a through <= 1.3.5.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23827

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in straps Strx Magic Floating Sidebar Maker strx-magic-floating-sidebar-maker allows Stored XSS.This issue affects Strx Magic Floating Sidebar Maker: from n/a through <= 1.4.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23818

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in pyko More Link Modifier more-link-modifier allows Stored XSS.This issue affects More Link Modifier: from n/a through <= 1.0.3.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23807

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jim2212001 Spiderpowa Embed PDF spiderpowa-embed-pdf allows Stored XSS.This issue affects Spiderpowa Embed PDF: from n/a through <= 1.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23822

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in alicornea Category Custom Fields categorycustomfields allows Cross Site Request Forgery.This issue affects Category Custom Fields: from n/a through <= 1.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23808

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Dutch van Andel Custom List Table Example custom-list-table-example allows Reflected XSS.This issue affects Custom List Table Example: from n/a through <= 1.4.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23805

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in itamarg SEOReseller Partner sr-partner allows Cross Site Request Forgery.This issue affects SEOReseller Partner: from n/a through <= 1.3.15.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23817

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in mahadirz MHR-Custom-Anti-Copy mhr-custom-anti-copy allows Stored XSS.This issue affects MHR-Custom-Anti-Copy: from n/a through <= 2.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23810

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Igor Sazonov Len Slider len-slider allows Reflected XSS.This issue affects Len Slider: from n/a through <= 2.0.11.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23801

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in FuzzGuard Style Admin style-admin allows Stored XSS.This issue affects Style Admin: from n/a through <= 1.4.3.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23804

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Shiv Prakash Tiwari WP Service Payment Form With Authorize.net wp-service-payment-form-with-authorizenet allows Reflected XSS.This issue affects WP Service Payment Form With Authorize.net: from n/a through <= 2.6.0.

    Published: 16 Jan 2025
    9.8
    Critical

    CVE-2025-23797

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Mike Selander WP Options Editor wp-options-editor allows Privilege Escalation.This issue affects WP Options Editor: from n/a through <= 1.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23795

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ghuger Easy FAQs easy-faqs allows Stored XSS.This issue affects Easy FAQs: from n/a through <= 3.2.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23800

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in nova706 OrangeBox orangebox allows Cross Site Request Forgery.This issue affects OrangeBox: from n/a through <= 3.0.0.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23802

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SteveSoehl WP-Revive Adserver wp-revive-adserver allows Stored XSS.This issue affects WP-Revive Adserver: from n/a through <= 2.2.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23796

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tushar Patel Easy Portfolio easy-portfolio allows Stored XSS.This issue affects Easy Portfolio: from n/a through <= 1.3.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23791

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mikakaltoft Horizontal Line Shortcode horizontal-line-shortcode allows Stored XSS.This issue affects Horizontal Line Shortcode: from n/a through <= 1.0.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23794

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _rccoder_ wp_amaps wp-amaps allows Stored XSS.This issue affects wp_amaps: from n/a through <= 1.7.

    Published: 16 Jan 2025
    7.6
    High

    CVE-2025-23780

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpha BPO Easy Code Snippets easy-code-snippets allows SQL Injection.This issue affects Easy Code Snippets: from n/a through <= 1.0.2.

    Published: 16 Jan 2025
    4.3
    Medium

    CVE-2025-23785

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in August Infotech AI Responsive Gallery Album ai-responsive-gallery-album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Responsive Gallery Album: from n/a through <= 1.4.

    Published: 16 Jan 2025
    5.4
    Medium

    CVE-2025-23778

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Pravin Durugkar User Sync ActiveCampaign registered-user-sync-activecampaign allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Sync ActiveCampaign: from n/a through <= 1.3.2.

    Published: 16 Jan 2025
    7.6
    High

    CVE-2025-23779

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in web-mv ResAds resads allows SQL Injection.This issue affects ResAds: from n/a through <= 2.0.5.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23777

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willowsconsulting GDPR Personal Data Reports gdpr-personal-data-reports allows Stored XSS.This issue affects GDPR Personal Data Reports: from n/a through <= 1.0.5.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23772

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eugenio Petulla’ imaGenius imagenius allows Stored XSS.This issue affects imaGenius: from n/a through <= 1.7.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23775

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WWP GMAPS for WPBakery Page Builder Free gmaps-for-visual-composer-free allows Stored XSS.This issue affects GMAPS for WPBakery Page Builder Free: from n/a through <= 1.2.

    Published: 16 Jan 2025
    4.3
    Medium

    CVE-2025-23765

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in w3speedster W3SPEEDSTER w3speedster-wp allows Cross Site Request Forgery.This issue affects W3SPEEDSTER: from n/a through <= 7.33.

    Published: 16 Jan 2025
    4.3
    Medium

    CVE-2025-23776

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ekaterir Cache Sniper for Nginx snipe-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cache Sniper for Nginx: from n/a through <= 1.0.4.2.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23783

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in carrotbits Greek Namedays Widget From Eortologio.Net greek-namedays-widget allows Stored XSS.This issue affects Greek Namedays Widget From Eortologio.Net: from n/a through <= 20191113.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23767

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revoxis Marmoset Viewer marmoset-viewer allows Stored XSS.This issue affects Marmoset Viewer: from n/a through <= 1.9.3.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23749

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in progpars.net mybb Last Topics mybb-last-topics allows Stored XSS.This issue affects mybb Last Topics: from n/a through <= 1.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23713

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in artanik Hack me if you can hack-me-if-you-can allows Stored XSS.This issue affects Hack me if you can: from n/a through <= 1.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23745

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tussendoor B.V. Call me Now call-me-now allows Stored XSS.This issue affects Call me Now: from n/a through <= 1.0.5.

    Published: 16 Jan 2025