cve/2025/CVE-2025-31610.md
2025-09-29 21:09:30 +02:00

18 lines
999 B
Markdown

### [CVE-2025-31610](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31610)
![](https://img.shields.io/static/v1?label=Product&message=Notification%20Bar%2C%20Sticky%20Notification%20Bar%2C%20Sticky%20Welcome%20Bar%20for%20any%20theme&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Improper%20Neutralization%20of%20Input%20During%20Web%20Page%20Generation%20('Cross-site%20Scripting')&color=brightgreen)
### Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gingerplugins Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme allows Stored XSS. This issue affects Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme: from n/a through 1.1.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds