CVE-2024-12239
- EPSS 1.47%
- Veröffentlicht 17.12.2024 03:15:06
- Zuletzt bearbeitet 15.04.2025 15:45:19
The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5 due to insufficient input sanitization and output escaping. This makes...
CVE-2024-43330
- EPSS 0.15%
- Veröffentlicht 18.08.2024 14:15:07
- Zuletzt bearbeitet 15.04.2025 15:10:00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack for Beaver Builder allows Reflected XSS.This issue affects PowerPack for Beaver Builder: from n/a before 2.37.4.
CVE-2024-37409
- EPSS 0.2%
- Veröffentlicht 22.07.2024 09:15:08
- Zuletzt bearbeitet 01.04.2026 16:17:23
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpack-addon-for-beaver-builder.This issue affects PowerPack Lite for Beaver Builder: from n/...
CVE-2024-37410
- EPSS 2.73%
- Veröffentlicht 09.07.2024 11:15:13
- Zuletzt bearbeitet 01.04.2026 16:17:23
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpack-addon-for-beaver-builder.This issue affects PowerPack Lite for Beav...
CVE-2024-2289
- EPSS 0.15%
- Veröffentlicht 09.04.2024 19:15:30
- Zuletzt bearbeitet 08.04.2026 19:21:03
The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in multiple elements in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user s...
CVE-2022-0176
- EPSS 0.23%
- Veröffentlicht 14.02.2022 12:15:16
- Zuletzt bearbeitet 15.04.2025 15:21:26
The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting