1011
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Bootstrap collapse allows Stored XSS. This issue affects Bootstrap collapse: from n/a t…
|
CWE-79
Cross-site Scripting
|
CVE-2025-26551
|
2025-02-13 23:16 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1012
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Kunal Shivale Global Meta Keyword & Description allows Stored XSS. This issue affects Global Meta Keyword & Description: from n/a through 2.3.
|
CWE-352
Origin Validation Error
|
CVE-2025-26550
|
2025-02-13 23:16 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1013
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in pa1 WP Html Page Sitemap allows Stored XSS. This issue affects WP Html Page Sitemap: from n/a through 2.2.
|
CWE-352
Origin Validation Error
|
CVE-2025-26549
|
2025-02-13 23:16 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1014
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin allows Stored XSS. This issue affects My Login Logout Plugin: from n/a through 2.4.
|
CWE-352
Origin Validation Error
|
CVE-2025-26547
|
2025-02-13 23:16 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1015
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in shisuh Related Posts Line-up-Exactly by Milliard allows Stored XSS. This issue affects Related Posts Line-up-Exactly by Milliard: from n/a through 0…
|
CWE-352
Origin Validation Error
|
CVE-2025-26545
|
2025-02-13 23:16 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1016
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petkivim Embed Google Map allows Stored XSS. This issue affects Embed Google Map: from n/a throug…
|
CWE-79
Cross-site Scripting
|
CVE-2025-26539
|
2025-02-13 23:16 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1017
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Prezi Embedder allows Stored XSS. This issue affects Prezi Embedder: from n/a throug…
|
CWE-79
Cross-site Scripting
|
CVE-2025-26538
|
2025-02-13 23:16 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1018
|
8.3 |
HIGH
Network
|
-
|
-
|
A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipu…
|
CWE-488
Exposure of Data Element to Wrong Session
|
CVE-2025-1247
|
2025-02-13 23:16 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1019
|
- |
|
-
|
-
|
Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malicious JavaScript code into a URL. When a user accesses that URL, the injected cod…
|
CWE-79
Cross-site Scripting
|
CVE-2025-1271
|
2025-02-13 22:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1020
|
- |
|
-
|
-
|
Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-1270
|
2025-02-13 22:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|