Medium - CVE-2025-1065 - The Visualizer: Tables and Charts Manager for...
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to,...
NA - CVE-2025-22888 - Movable Type contains a stored cross-site...
Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be executed on a logged-in user's web...
NA - CVE-2025-24841 - Movable Type contains a stored cross-site...
Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may...
NA - CVE-2025-25054 - Movable Type contains a reflected cross-site...
Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while...
Medium - CVE-2024-11335 - The UltraEmbed – Advanced Iframe Plugin For...
The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframe'...
Medium - CVE-2024-11753 - The UMich OIDC Login plugin for WordPress is...
The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_button' shortcode in all versions up to, and including, 1.2.0 due...
Medium - CVE-2024-11778 - The CanadaHelps Embedded Donation Form plugin...
The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedcdn' shortcode in all versions up to, and including,...
Medium - CVE-2024-12069 - The Lexicata plugin for WordPress is vulnerable...
The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including,...
Medium - CVE-2024-12339 - The Digihood HTML Sitemap plugin for WordPress...
The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' parameter in all versions up to, and including, 3.1.1 due to insufficient input...