CVE-2025-58920 - WordPress Cerato theme <= 2.2.18 - Reflected Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2025-58920
Published : April 10, 2026, 1:25 p.m. | 40 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability ...
Related Vulnerabilities
- CVE-2026-33737: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use sim MEDIUM
- CVE-2026-22560: An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected MEDIUM
- CVE-2026-31939: Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exe HIGH
- CVE-2026-33141: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Referenc MEDIUM
- CVE-2026-29145: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v MEDIUM
Related Coverage
Threat Actors