Vulnerability Database

308,379

Total vulnerabilities in the database

CVE-2025-3650

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

  • Published: Sep 12, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-3650
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

No CWE or OWASP classifications available.