CVE-2025-27793 – Vega JavaScript Injection Vulnerability

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 5.32.0, corresponding to vega-functions prior to version 5.17.0, users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs, unless the library was used with the `vega-interpreter`. Vega version 5.32.0 and vega-functions […]

CVE-2025-26738 – Graham Quick Interest Slider Cross-site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-26738 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]

CVE-2025-26737 – YudleeThemes City Store Cross-Site Scripting

The following table lists the changes that have been made to the CVE-2025-26737 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]

CVE-2025-26736 – Viktoras MorningTime Lite Cross-site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-26736 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]

CVE-2025-26734 – PeregrineThemes Hester Stored Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-26734 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]

CVE-2025-26732 – BurgerThemes StoreBiz Cross-site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-26732 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]

CVE-2025-26731 – Repute Infosystems ARPrice Cross-site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-26731 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]

CVE-2025-26619 – Vega JavaScript Injection Vulnerability

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In `vega` 5.30.0 and lower and in `vega-functions` 5.15.0 and lower , it was possible to call JavaScript functions from the Vega expression language that were not meant to be supported. The issue is patched in `vega` `5.31.0` and […]

CVE-2025-25100 – Vicoracano Cazamba CSRF Reflected XSS

The following table lists the changes that have been made to the CVE-2025-25100 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]

CVE-2025-25086 – WPDeveloper Secret Meta CSRF Reflected XSS

The following table lists the changes that have been made to the CVE-2025-25086 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]