Latest CVE Feed
-
5.4
MEDIUMCVE-2023-0015
In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intel... Read more
Affected Products : business_objects_business_intelligence_platform- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0111
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.... Read more
Affected Products : memos- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0081
The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cr... Read more
Affected Products : monsterinsights- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0065
The i2 Pros & Cons WordPress plugin through 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more
Affected Products : i2_pros_\&_cons- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0150
The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to p... Read more
Affected Products : cloak_front_end_email- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2022-4946
The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to a... Read more
Affected Products : frontend_post_wordpress_plugin- Published: Jun. 05, 2023
- Modified: Jan. 08, 2025
-
5.4
MEDIUMCVE-2022-4762
The Materialis Companion WordPress plugin before 1.3.40 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting... Read more
Affected Products : materialis_companion- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2022-4760
The OneClick Chat to Order WordPress plugin before 1.0.4.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Script... Read more
Affected Products : oneclick_chat_to_order- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2022-4834
The CPT Bootstrap Carousel WordPress plugin through 1.12 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scriptin... Read more
Affected Products : cpt_bootstrap_carousel- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2022-4756
The My YouTube Channel WordPress plugin before 3.23.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting a... Read more
Affected Products : my_youtube_channel- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2022-4775
The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
- Published: Jan. 23, 2023
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2022-4833
The YourChannel: Everything you want in a YouTube plugin WordPress plugin before 1.2.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perf... Read more
Affected Products : yourchannel- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2022-4787
Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : shortcodes- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2022-4790
The WP Google My Business Auto Publish WordPress plugin before 3.4 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : auto_publish_for_google_my_business- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2022-4754
The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and a... Read more
Affected Products : easy_social_box- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2022-4717
The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting a... Read more
- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2022-4782
The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : clickfunnels- Published: Aug. 16, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4757
The List Pages Shortcode WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting ... Read more
Affected Products : list_pages_shortcode- Published: Feb. 27, 2023
- Modified: Mar. 10, 2025
-
5.4
MEDIUMCVE-2022-4751
The Word Balloon WordPress plugin before 4.19.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : word_balloon- Published: Jan. 23, 2023
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2022-4825
The WP-ShowHide WordPress plugin before 1.05 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks wh... Read more
Affected Products : download_wp-showhide- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025