NA - CVE-2024-13875 - The WP-PManager WordPress plugin through 1.2...
The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...
NA - CVE-2024-13876 - The mEintopf WordPress plugin through 0.2.1...
The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...
NA - CVE-2024-13877 - The Passbeemedia Web Push Notification...
The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting...
NA - CVE-2024-13878 - The SpotBot WordPress plugin through 0.1.8 does...
The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...
NA - CVE-2024-13880 - The My Quota WordPress plugin through 1.0.8...
The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...
NA - CVE-2024-13881 - The Link My Posts WordPress plugin through 1.0...
The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
Medium - CVE-2025-1314 - The Custom Twitter Feeds – A Tweets Widget or X...
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or...
Medium - CVE-2025-1766 - The Event Manager, Events Calendar, Tickets,...
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
High - CVE-2025-1770 - The Event Manager, Events Calendar, Tickets,...
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the...
NA - CVE-2025-22228 - BCryptPasswordEncoder.matches(CharSequence,Stri...
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.