Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30.
We have discovered 356 live websites that are affected by CVE-2025-67918.
| Product | |
| Category | Wordpress Themes |
| Vulnerable Domains | 356 live websites (100% of Woffice install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 30 versions ( 91% of all versions) |
| 109 websites | |
| 38 websites | |
| 29 websites | |
| 26 websites | |
| 22 websites | |
| 19 websites | |
| 16 websites | |
| 14 websites | |
| 11 websites | |
| 9 websites |
| .com | 118 websites |
| .org | 31 websites |
| .fr | 16 websites |
| .com.au | 16 websites |
| .de | 16 websites |
| .net | 13 websites |
| .nl | 13 websites |
| .eu | 10 websites |
| .es | 9 websites |
| .ru | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | ***,*** | ||
| ********.**********.com | ***,*** | ||
| *****.*******.com | ***,*** | ||
| ***************.de | ***,*** | ||
| *******.pt | ***,*** | ||
| ********.org | ***,*** | ||
| **.**************.pt | *,***,*** | ||
| **********.com | *,***,*** | ||
| *****.***.br | *,***,*** | ||
| ****.*********.it | *,***,*** |