231
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFarmer Ultimate Subscribe allows Reflected XSS. This issue affects Ultimate Subscribe: from n/a through 1.3.
New
|
CWE-352
Origin Validation Error
|
CVE-2025-23806
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
232
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in PQINA Snippy allows Reflected XSS. This issue affects Snippy: from n/a through 1.4.1.
New
|
CWE-352
Origin Validation Error
|
CVE-2025-23803
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
233
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eliott Robson Mass Messaging in BuddyPress allows Reflected XSS. This issue affects Mass Messagin…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23798
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
234
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows SQL Injection. This issue affects Co…
New
|
CWE-89
SQL Injection
|
CVE-2025-23784
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
235
|
- |
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WM Options Import Export allows Retrieve Embedded Sensitive Data. This issue affects WM Options Import Export: from n/a thr…
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2025-23781
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
236
|
- |
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WPDB to Sql allows Retrieve Embedded Sensitive Data. This issue affects WPDB to Sql: from n/a through 1.2.
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2025-23774
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
237
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Fast Tube allows Reflected XSS. This issue affects Fast Tube: from n/a through 2.3.1.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23770
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
238
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Content Mirror allows Reflected XSS. This issue affects Content Mirror: from n/a through…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23769
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
239
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound InFunding allows Reflected XSS. This issue affects InFunding: from n/a through 1.0.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23768
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
240
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pootle button allows Reflected XSS. This issue affects Pootle button: from n/a through 1…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23758
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|