Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nextmove MEDIUM 6.5
CVE-2025-62969

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove Lite woo-thank-you-page-next…

Fix: after 2.23.0
Fix from $1,600 2025-10-27
Nextmove HIGH 7.1
CVE-2025-52735

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove Lite woo-thank-you-page-next…

Fix: after 2.23.0
Fix from $1,950 2025-10-22
Finale MEDIUM 5.4
CVE-2024-12589

The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via th…

Fix: 2.20.0+
Fix from $1,600 2025-03-12
Finale MEDIUM 6.5
CVE-2023-47180

Missing Authorization vulnerability in XLPlugins Finale Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…

Fix: 2.17.0+
Fix from $1,600 2025-01-02
Finale HIGH 8.8
CVE-2024-30485

Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.

Fix: 2.18.1+
Fix from $1,950 2024-06-09
Nextmove HIGH 8.8
CVE-2024-25092

Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.

Fix: 2.18.0+
Fix from $1,950 2024-06-09
Finale MEDIUM 5.3
CVE-2024-1120

The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulne…

Fix: 2.18.0 / 2.18.1+
Fix from $1,600 2024-03-01
Woo Confirmation Email MEDIUM 6.1
CVE-2023-39162

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions.

Fix: after 3.5.0
Fix from $1,600 2023-09-04