Known Vulnerabilities for Widgets by Yahoo
Listed below are 1 of the newest known vulnerabilities associated with "Widgets" by "Yahoo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-68595 | Missing Authorization vulnerability in Trustindex Widgets for Social Photo Feed social-photo-feed-widget allows Exploiting In... | Not Provided | 2025-12-24 | 2026-04-01 |
| CVE-2025-60128 | Missing Authorization vulnerability in WP Delicious Delisho dr-widgets-blocks allows Exploiting Incorrectly Configured Access... | Not Provided | 2025-09-26 | 2026-04-01 |
| CVE-2025-59574 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel Engine WP Tra... | Not Provided | 2025-09-22 | 2026-04-01 |
| CVE-2025-58853 | Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Popping Sidebars and Widgets Light popping-sidebars-and-widgets-... | Not Provided | 2025-09-05 | 2026-04-01 |
| CVE-2025-58029 | Missing Authorization vulnerability in Sumit Singh Classic Widgets with Block-based Widgets classic-widgets-with-block-based-... | Not Provided | 2025-09-22 | 2026-04-01 |
| CVE-2025-57989 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brajesh Singh WordPress... | Not Provided | 2025-09-22 | 2026-04-01 |
| CVE-2025-48354 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Smart Widgets Better... | Not Provided | 2025-08-28 | 2026-04-01 |
| CVE-2025-46526 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janekniefeldt My Custom... | Not Provided | 2025-05-23 | 2026-04-01 |
| CVE-2025-31869 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black... | Not Provided | 2025-04-01 | 2026-04-01 |
| CVE-2025-31539 | Missing Authorization vulnerability in Blocksera Cryptocurrency Widgets Pack cryptocurrency-widgets-pack allows Exploiting In... | Not Provided | 2025-03-31 | 2026-04-01 |