CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2025-23743

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in MartijnScheijbeler Social Analytics social-analytics allows Stored XSS.This issue affects Social Analytics: from n/a through <= 0.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23717

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in itmooti Theme My Ontraport Smartform theme-my-ontraport-smartform allows Stored XSS.This issue affects Theme My Ontraport Smartform: from n/a through <= 1.2.11.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23720

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Marco Castelluccio Web Push web-push allows Stored XSS.This issue affects Web Push: from n/a through <= 1.4.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23702

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Schalk Burger Anonymize Links anonymize-links allows Stored XSS.This issue affects Anonymize Links: from n/a through <= 1.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23712

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in kapostintegrations Kapost kapost-byline allows Stored XSS.This issue affects Kapost: from n/a through <= 2.2.9.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23715

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in RaymondDesign Post & Page Notes post-page-notes allows Stored XSS.This issue affects Post & Page Notes: from n/a through <= 0.1.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23703

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in cstoltenkamp Free MailClient FMC mailclient allows Stored XSS.This issue affects Free MailClient FMC: from n/a through <= 1.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23710

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Mayur Sojitra Flying Twitter Birds flying-twitter-birds allows Stored XSS.This issue affects Flying Twitter Birds: from n/a through <= 1.8.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23708

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Dominic Fallows DF Draggable df-draggable allows Stored XSS.This issue affects DF Draggable: from n/a through <= 1.13.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23698

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ivanra10 WP Custom Google Search wp-custom-google-search allows Stored XSS.This issue affects WP Custom Google Search: from n/a through <= 1.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23694

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in shabboscommerce Shabbos and Yom Tov shabbos-and-yom-tov allows Stored XSS.This issue affects Shabbos and Yom Tov: from n/a through <= 1.9.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23699

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techmix Event Countdown Timer Plugin by TechMix event-countdown-timer allows Reflected XSS.This issue affects Event Countdown Timer Plugin by TechMix: from n/a through <= 1.4.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23692

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in artanik Slider for Writers slider-for-writers allows Stored XSS.This issue affects Slider for Writers: from n/a through <= 1.3.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23690

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ArtkanMedia Book a Place book-a-place allows Stored XSS.This issue affects Book a Place: from n/a through <= 0.7.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23675

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sana Ullah Import Users to MailChimp import-users-to-mailchimp allows Stored XSS.This issue affects Import Users to MailChimp: from n/a through <= 1.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23689

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import allows Stored XSS.This issue affects Blogger Image Import: from 2.1 through n/a.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23677

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in DSmidge HTTP to HTTPS link changer by Eyga.net https-links-in-content allows Stored XSS.This issue affects HTTP to HTTPS link changer by Eyga.net: from n/a through <= 0.2.4.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23673

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in dkukral Email on Publish email-on-publish allows Stored XSS.This issue affects Email on Publish: from n/a through <= 1.5.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23693

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in uosiu Secure CAPTCHA secure-captcha allows Stored XSS.This issue affects Secure CAPTCHA: from n/a through <= 1.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23691

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Braulio Aquino Send to Twitter send-to-twitter allows Stored XSS.This issue affects Send to Twitter: from n/a through <= 1.7.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23665

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ravi Kumar Vanukuru RSV GMaps rsv-google-maps allows Stored XSS.This issue affects RSV GMaps: from n/a through <= 1.5.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23644

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in justin.kuepper QuoteMedia Tools quotemedia-tools allows DOM-Based XSS.This issue affects QuoteMedia Tools: from n/a through <= 1.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23661

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ryscript NV Slider nv-slider allows Stored XSS.This issue affects NV Slider: from n/a through <= 1.6.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23649

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kreg Steppe Auphonic Importer auphonic-importer allows Stored XSS.This issue affects Auphonic Importer: from n/a through <= 1.5.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23654

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in krolow Twitter Post twitterpost allows Stored XSS.This issue affects Twitter Post: from n/a through <= 0.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23664

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Real Seguro Viagem Real Seguro Viagem seguro-viagem allows Stored XSS.This issue affects Real Seguro Viagem: from n/a through <= 2.0.5.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23660

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in waltercerrudo MFPlugin mfplugin allows Stored XSS.This issue affects MFPlugin: from n/a through <= 1.3.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23662

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ryscript WP Panoramio wp-panoramio allows Stored XSS.This issue affects WP Panoramio: from n/a through <= 1.5.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23659

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in hernanjh MercadoLibre Integration mercadolibre-integration allows Stored XSS.This issue affects MercadoLibre Integration: from n/a through <= 1.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23642

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pflonk Sidebar-Content from Shortcode sidebar-content-from-shortcode allows DOM-Based XSS.This issue affects Sidebar-Content from Shortcode: from n/a through <= 2.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23640

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan Rename Author Slug rename-author-slug allows Stored XSS.This issue affects Rename Author Slug: from n/a through <= 1.2.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23623

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mahesh Bisen Contact Form 7 – CCAvenue Add-on cf7-cc-avenue-add-on allows Reflected XSS.This issue affects Contact Form 7 – CCAvenue Add-on: from n/a through <= 1.0.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23641

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PowieT Powie's pLinks PagePeeker plinks allows DOM-Based XSS.This issue affects Powie's pLinks PagePeeker: from n/a through <= 1.0.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23627

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in frenchsquared Comment-Emailer comment-emailer allows Stored XSS.This issue affects Comment-Emailer: from n/a through <= 1.0.5.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23639

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan MDC YouTube Downloader mdc-youtube-downloader allows Stored XSS.This issue affects MDC YouTube Downloader: from n/a through <= 3.0.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23573

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in sammyb WP Background Tile wp-background-tile allows Stored XSS.This issue affects WP Background Tile: from n/a through <= 1.0.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23618

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in starise Twitter Shortcode twitter-shortcode allows Stored XSS.This issue affects Twitter Shortcode: from n/a through <= 0.9.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23577

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Word Freshener word-freshener allows Stored XSS.This issue affects Word Freshener: from n/a through <= 1.3.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23559

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Stepan Stepasyuk MemeOne allows Stored XSS.This issue affects MemeOne: from n/a through 2.0.5.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23617

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in cybio Floatbox Plus floatbox-plus allows Stored XSS.This issue affects Floatbox Plus: from n/a through <= 1.4.4.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23567

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tamer Ziady GDReseller gdreseller allows Stored XSS.This issue affects GDReseller: from n/a through <= 1.6.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23547

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shawfactor LH Login Page lh-login-page allows Reflected XSS.This issue affects LH Login Page: from n/a through <= 2.14.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23569

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kelvin Ng Shortcode in Comment shortcode-in-comment allows Stored XSS.This issue affects Shortcode in Comment: from n/a through <= 1.1.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23620

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trof Captchelfie – Captcha by Selfie captchelfie-captcha-by-selfie allows Reflected XSS.This issue affects Captchelfie – Captcha by Selfie: from n/a through <= 1.0.7.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23572

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Dave Konopka UpDownUpDown updownupdown-postcomment-voting allows Stored XSS.This issue affects UpDownUpDown: from n/a through <= 1.1.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23557

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kathleen Malone Find Your Reps find-your-reps allows Stored XSS.This issue affects Find Your Reps: from n/a through <= 1.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23560

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in plumwd Web Testimonials web-testimonials allows Stored XSS.This issue affects Web Testimonials: from n/a through <= 1.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23566

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in syedamirhussain91 Custom Post custom-post-type-gui allows Stored XSS.This issue affects Custom Post: from n/a through <= 1.0.

    Published: 16 Jan 2025
    8.8
    High

    CVE-2025-23528

    Last Modified: 29 Apr 2026

    Incorrect Privilege Assignment vulnerability in Mosterd3d DD Roles dd-roles allows Privilege Escalation.This issue affects DD Roles: from n/a through <= 4.1.

    Published: 16 Jan 2025
    8.8
    High

    CVE-2025-23532

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Regios MyAnime Widget myanime-widget allows Privilege Escalation.This issue affects MyAnime Widget: from n/a through <= 1.0.

    Published: 16 Jan 2025