1051
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Benjamin Piwowarski PAPERCITE allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PAPERCITE: from n/a through 0.5.18.
|
CWE-862
Missing Authorization
|
CVE-2025-23849
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1052
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ivan Chernyakov LawPress – Law Firm Website Management allows Reflected XSS. This issue affects L…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23756
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1053
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ulrich Sossou The Loops allows Reflected XSS. This issue affects The Loops: from n/a through 1.0.…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23754
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1054
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound CGD Arrange Terms allows Reflected XSS. This issue affects CGD Arrange Terms: from n/a t…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23752
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1055
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nurul Amin, Mohammad Saiful Islam WP Smart Tooltip allows Stored XSS. This issue affects WP Smart…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23669
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1056
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Saul Morales Pacheco Donate visa allows Stored XSS. This issue affects Donate visa: from n/a through 1.0.0.
|
CWE-862
Missing Authorization
|
CVE-2025-23656
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1057
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Lau CubePM allows Reflected XSS. This issue affects CubePM: from n/a through 1.0.
|
CWE-79
Cross-site Scripting
|
CVE-2025-23574
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1058
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David F. Carr RSVPMaker Volunteer Roles allows Reflected XSS. This issue affects RSVPMaker Volunt…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23531
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1059
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Blokhaus Minterpress allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Minterpress: from n/a through 1.0.5.
|
CWE-862
Missing Authorization
|
CVE-2025-23529
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1060
|
- |
|
-
|
-
|
The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary menu via a CSRF attack
|
-
|
CVE-2024-12774
|
2025-01-28 00:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|