CVE-2026-61981
- EPSS 0.1%
- Veröffentlicht 23.07.2026 11:18:32
- Zuletzt bearbeitet 23.07.2026 16:17:46
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
CVE-2026-57682
- EPSS 0.19%
- Veröffentlicht 02.07.2026 11:15:38
- Zuletzt bearbeitet 02.07.2026 20:17:05
Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
CVE-2026-53742
- EPSS 0.14%
- Veröffentlicht 10.06.2026 20:39:46
- Zuletzt bearbeitet 23.07.2026 09:10:00
Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a ...
CVE-2026-53741
- EPSS 0.14%
- Veröffentlicht 10.06.2026 20:39:45
- Zuletzt bearbeitet 23.07.2026 09:10:00
Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every ...
CVE-2026-7209
- EPSS 0.2%
- Veröffentlicht 02.05.2026 03:36:43
- Zuletzt bearbeitet 05.05.2026 19:17:22
The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to insufficient input sanitization and output escaping o...
CVE-2025-67576
- EPSS 0.26%
- Veröffentlicht 09.12.2025 14:14:13
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through <= 8.8.3.
CVE-2025-67465
- EPSS 0.13%
- Veröffentlicht 09.12.2025 14:13:55
- Zuletzt bearbeitet 27.04.2026 18:16:39
Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Cross Site Request Forgery.This issue affects Simple Link Directory: from n/a through <= 8.8.3.
CVE-2025-49901
- EPSS 0.69%
- Veröffentlicht 22.10.2025 14:32:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1.
CVE-2025-48297
- EPSS 0.23%
- Veröffentlicht 20.08.2025 08:03:24
- Zuletzt bearbeitet 23.04.2026 15:31:03
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1...
CVE-2025-32297
- EPSS 0.25%
- Veröffentlicht 04.07.2025 11:18:06
- Zuletzt bearbeitet 23.04.2026 15:28:55
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows SQL Injection.This issue affects Simple Link Directory: from n/a through < 14.8.1...