Ideabox

Powerpack For Beaver Builder

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.12%
  • Veröffentlicht 17.12.2024 03:15:06
  • Zuletzt bearbeitet 15.04.2025 15:45:19

The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5 due to insufficient input sanitization and output escaping. This makes...

  • EPSS 0.15%
  • Veröffentlicht 18.08.2024 14:15:07
  • Zuletzt bearbeitet 15.04.2025 15:10:00

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack for Beaver Builder allows Reflected XSS.This issue affects PowerPack for Beaver Builder: from n/a before 2.37.4.

  • EPSS 0.07%
  • Veröffentlicht 22.07.2024 09:15:08
  • Zuletzt bearbeitet 15.04.2025 15:21:26

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Stored XSS.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3....

  • EPSS 0.93%
  • Veröffentlicht 09.07.2024 11:15:13
  • Zuletzt bearbeitet 15.04.2025 15:21:26

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Path Traversal.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3.0.3.

  • EPSS 0.15%
  • Veröffentlicht 09.04.2024 19:15:30
  • Zuletzt bearbeitet 15.04.2025 15:45:34

The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in multiple elements in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user s...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 14.02.2022 12:15:16
  • Zuletzt bearbeitet 15.04.2025 15:21:26

The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting