CVE-2025-64383

Severity
6.5MEDIUM
EPSS
0.0%
top 93.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 13

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks allows Stored XSS.This issue affects Qi Blocks: from n/a through <= 1.4.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:LExploitability: 2.3 | Impact: 3.7

Affected Packages1 packages

CVEListV5qode/qi_blocks1.4.3

🔴Vulnerability Details

2
CVEList
WordPress Qi Blocks plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability2025-11-13
GHSA
GHSA-gjc9-grw9-5m5q: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks allows Stored XSS2025-11-13
CVE-2025-64383 (MEDIUM CVSS 6.5) | Improper Neutralization of Input Du | cvebase.io