CVE-2025-31537: Madfishdigital Bulk Noindex & Nofollow Toolkit

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in madfishdigital Bulk NoIndex & NoFollow Toolkit bulk-noindex-nofollow-toolkit-by-mad-fish allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through <= 2.16.

Affected products

  • Madfishdigital Bulk Noindex & Nofollow Toolkit: up to and including 2.16

Published 2025-04-01. Last modified 2026-06-17.