1651
|
- |
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zankover Fami Sales Popup allows PHP Local File Inclusion. This issue affects …
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2025-25141
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1652
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Scriptonite Simple User Profile allows Stored XSS. This issue affects Simple User Profile: from n/a through 1.9.
|
CWE-352
Origin Validation Error
|
CVE-2025-25140
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1653
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Cynob IT Consultancy WP Custom Post RSS Feed allows Stored XSS. This issue affects WP Custom Post RSS Feed: from n/a through 1.0.0.
|
CWE-352
Origin Validation Error
|
CVE-2025-25139
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1654
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Rishi On Page SEO + Whatsapp Chat Button allows Stored XSS. This issue affects On Page SEO + Whatsapp Chat Button: from n/a through 2.0.0.
|
CWE-352
Origin Validation Error
|
CVE-2025-25138
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1655
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shujahat21 Optimate Ads allows Stored XSS. This issue affects Optimate Ads: from n/a through 1.0.…
|
CWE-79
Cross-site Scripting
|
CVE-2025-25136
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1656
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar allows Stored XSS. This issue affects Custom Links On Admin Dashboard Toolbar: from n/a thro…
|
CWE-352
Origin Validation Error
|
CVE-2025-25135
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1657
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in orlandolac Facilita Form Tracker allows Stored XSS. This issue affects Facilita Form Tracker: from n/a through 1.0.
|
CWE-352
Origin Validation Error
|
CVE-2025-25128
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1658
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in zmseo ZMSEO allows Stored XSS. This issue affects ZMSEO: from n/a through 1.14.1.
|
CWE-352
Origin Validation Error
|
CVE-2025-25126
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1659
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in CyrilG Fyrebox Quizzes allows Stored XSS. This issue affects Fyrebox Quizzes: from n/a through 2.7.
|
CWE-352
Origin Validation Error
|
CVE-2025-25125
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1660
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in xdark Easy Related Posts allows Stored XSS. This issue affects Easy Related Posts: from n/a through 2.0.2.
|
CWE-352
Origin Validation Error
|
CVE-2025-25123
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|