A vulnerability was found in Pretty Links Plugin up to 1.5.5 on WordPress. It has been classified as problematic. Affected is an unknown function of the component URL Parameter Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2011-4595. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in MediaView Plugin up to 1.1.2 on WordPress. This affects an unknown part. The manipulation of the argument ID leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-2481. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. This vulnerability affects the function getBookList of the file /admin/bookList?page=1&limit=10. The manipulation of the argument condition leads to sql injection.
This vulnerability was named CVE-2025-2831. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity.
This vulnerability is traded as CVE-2025-2833. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2025-2835. The attack can be launched remotely. Furthermore, there is an exploit available.