CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-22805

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Skill Bar skillbars allows Stored XSS.This issue affects Skill Bar: from n/a through <= 1.2.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22806

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor black-widgets allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through <= 1.3.8.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22807

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Responsive Flickr Slideshow mobile-friendly-flickr-slideshow allows Stored XSS.This issue affects Responsive Flickr Slideshow: from n/a through <= 2.6.0.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22808

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Surbma Surbma | Premium WP surbma-premium-wp allows DOM-Based XSS.This issue affects Surbma | Premium WP: from n/a through <= 9.0.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22809

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in theme funda PDF Catalog Woocommerce pdf-catalog-woocommerce allows DOM-Based XSS.This issue affects PDF Catalog Woocommerce: from n/a through <= 2.0.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22810

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phi Phan Content Blocks Builder content-blocks-builder allows Stored XSS.This issue affects Content Blocks Builder: from n/a through <= 2.7.6.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22811

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristian Stan MT Addons for Elementor mt-addons-for-elementor allows Stored XSS.This issue affects MT Addons for Elementor: from n/a through <= 1.0.6.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22812

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aezaz Shaikh News Ticker Widget for Elementor news-ticker-widget-for-elementor allows Stored XSS.This issue affects News Ticker Widget for Elementor: from n/a through <= 1.3.2.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22813

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot conversational-forms allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through <= 1.4.2.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22814

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Admin Theme zephyr-modern-admin-theme allows Cross Site Request Forgery.This issue affects Zephyr Admin Theme: from n/a through <= 1.4.1.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22815

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Button Block button-block allows Stored XSS.This issue affects Button Block: from n/a through <= 1.1.9.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22817

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra bp-profile-shortcodes-extra allows Stored XSS.This issue affects BP Profile Shortcodes Extra: from n/a through <= 2.6.0.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22818

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in S3Bubble S3Player – WooCommerce & Elementor Integration drm-protected-video-streaming allows Stored XSS.This issue affects S3Player – WooCommerce & Elementor Integration: from n/a through <= 4.2.1.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22819

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roberto Bottalico Qr Code and Barcode Scanner Reader qr-code-and-barcode-scanner-reader allows Stored XSS.This issue affects Qr Code and Barcode Scanner Reader: from n/a through <= 1.0.0.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22820

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goldsounds VR Views vr-views allows Stored XSS.This issue affects VR Views: from n/a through <= 1.5.1.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22821

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vfthemes StorePress storepress allows DOM-Based XSS.This issue affects StorePress: from n/a through <= 1.0.12.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22822

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bishawjit-das wp custom countdown wp-custom-countdown allows Stored XSS.This issue affects wp custom countdown: from n/a through <= 2.8.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22823

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jtwerdy Genesis Style Shortcodes genesis-style-shortcodes allows DOM-Based XSS.This issue affects Genesis Style Shortcodes: from n/a through <= 1.0.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22824

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lucia.intelisano Live Flight Radar live-flight-radar allows Stored XSS.This issue affects Live Flight Radar: from n/a through <= 1.0.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22826

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Sell Digital Downloads sell-digital-downloads allows Stored XSS.This issue affects Sell Digital Downloads: from n/a through <= 2.2.7.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22827

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in joomag WP Joomag wp-joomag allows DOM-Based XSS.This issue affects WP Joomag: from n/a through <= 2.5.2.

    Published: 9 Jan 2025
    8.8
    High

    CVE-2024-13284

    Last Modified: 2 Sept 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.

    Published: 9 Jan 2025
    6.1
    Medium

    CVE-2024-13283

    Last Modified: 2 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.9.

    Published: 9 Jan 2025
    8.8
    High

    CVE-2024-13282

    Last Modified: 2 Sept 2025

    Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.

    Published: 9 Jan 2025
    9.1
    Critical

    CVE-2024-13281

    Last Modified: 2 Sept 2025

    Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.

    Published: 9 Jan 2025
    9.8
    Critical

    CVE-2024-13280

    Last Modified: 2 Sept 2025

    Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.

    Published: 9 Jan 2025
    9.8
    Critical

    CVE-2024-13279

    Last Modified: 2 Sept 2025

    Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.

    Published: 9 Jan 2025
    9.1
    Critical

    CVE-2024-13278

    Last Modified: 2 Sept 2025

    Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.

    Published: 9 Jan 2025
    9.1
    Critical

    CVE-2024-13277

    Last Modified: 2 Sept 2025

    Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.

    Published: 9 Jan 2025
    7.5
    High

    CVE-2024-13276

    Last Modified: 2 Sept 2025

    Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13275

    Last Modified: 2 Sept 2025

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13274

    Last Modified: 14 Jan 2025

    Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-13273

    Last Modified: 28 Aug 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.

    Published: 9 Jan 2025
    6.3
    Medium

    CVE-2024-13272

    Last Modified: 27 Aug 2025

    Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.

    Published: 9 Jan 2025
    4.3
    Medium

    CVE-2024-13271

    Last Modified: 27 Aug 2025

    Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.

    Published: 9 Jan 2025
    4.3
    Medium

    CVE-2024-13270

    Last Modified: 27 Aug 2025

    Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: from 0.0.0 before 4.0.1.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13269

    Last Modified: 27 Aug 2025

    Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This issue affects Advanced Varnish: from 0.0.0 before 4.0.11.

    Published: 9 Jan 2025
    6.8
    Medium

    CVE-2024-13268

    Last Modified: 27 Aug 2025

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno allows PHP Local File Inclusion.This issue affects Opigno: from 7.X-1.0 before 7.X-1.23.

    Published: 9 Jan 2025
    7.5
    High

    CVE-2024-13267

    Last Modified: 27 Aug 2025

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13266

    Last Modified: 27 Aug 2025

    Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4.

    Published: 9 Jan 2025
    7.5
    High

    CVE-2024-13265

    Last Modified: 27 Aug 2025

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.

    Published: 9 Jan 2025
    9.8
    Critical

    CVE-2024-13264

    Last Modified: 27 Aug 2025

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2.

    Published: 9 Jan 2025
    5.5
    Medium

    CVE-2024-13263

    Last Modified: 27 Aug 2025

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno group manager allows PHP Local File Inclusion.This issue affects Opigno group manager: from 0.0.0 before 3.1.1.

    Published: 9 Jan 2025
    4.8
    Medium

    CVE-2024-13262

    Last Modified: 28 Aug 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Password allows Cross-Site Scripting (XSS).This issue affects View Password: from 0.0.0 before 6.0.4.

    Published: 9 Jan 2025
    3.5
    Low

    CVE-2024-13261

    Last Modified: 27 Aug 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before 1.1.0-beta3.

    Published: 9 Jan 2025
    8.8
    High

    CVE-2024-13260

    Last Modified: 4 Jun 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.

    Published: 9 Jan 2025
    7.5
    High

    CVE-2024-13259

    Last Modified: 4 Jun 2025

    Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.

    Published: 9 Jan 2025
    9.8
    Critical

    CVE-2024-13258

    Last Modified: 4 Jun 2025

    Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13257

    Last Modified: 4 Jun 2025

    Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.

    Published: 9 Jan 2025
    7.5
    High

    CVE-2024-13256

    Last Modified: 4 Jun 2025

    Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.

    Published: 9 Jan 2025