531
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Hemnath Mouli WC Wallet allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WC Wallet: from n/a through 2.2.0.
|
CWE-862
Missing Authorization
|
CVE-2025-23527
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
532
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikashsrivastava1111989 VSTEMPLATE Creator allows Reflected XSS. This issue affects VSTEMPLATE Cr…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23491
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
533
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in idIA Tech Catalog Importer, Scraper & Crawler allows Reflected XSS. This issue affects Catalog Im…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22775
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
534
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Abinav Thakuri WordPress Signature allows Cross Site Request Forgery. This issue affects WordPress Signature: from n/a through 0.1.
|
CWE-352
Origin Validation Error
|
CVE-2025-22704
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
535
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder allows Stored XSS. This issue affects Forge – Front-End Page Builder: from n/a through 1.4.6.
|
CWE-352
Origin Validation Error
|
CVE-2025-22703
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
536
|
- |
|
-
|
-
|
Server-Side Request Forgery (SSRF) vulnerability in NotFound Traveler Layout Essential For Elementor. This issue affects Traveler Layout Essential For Elementor: from n/a through 1.0.8.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-22701
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
537
|
- |
|
-
|
-
|
Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support. This issue affects Nirweb support: from n/a through 3.0.3.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-22695
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
538
|
- |
|
-
|
-
|
Missing Authorization vulnerability in theDotstore Hide Shipping Method For WooCommerce. This issue affects Hide Shipping Method For WooCommerce: from n/a through 1.5.0.
|
CWE-862
Missing Authorization
|
CVE-2025-22694
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
539
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery Contest Gallery allows SQL Injection. This issue affects Contest Gallery: from n/…
|
CWE-89
SQL Injection
|
CVE-2025-22693
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
540
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel allows SQL Injection. This issue affects WP Travel: from n/a through 10.1.0.
|
CWE-89
SQL Injection
|
CVE-2025-22691
|
2025-02-4 00:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|