CVE-2025-10125Medium· 6.4▾ SunlitThe Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user su…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66472Medium· 6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2026-63216Medium· 5.3Zammad is a web based open source helpdesk/customer support system
CVE-2026-57440High· 7.5The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services
CVE-2026-91130Critical· 9.3Home Assistant is open source home automation software focused on local control and privacy
CVE-2026-68919High· 7.0GoCD is a continuous deliver server
CVE-2026-52741High· 7.5GoCD is a continuous deliver server