CVE-2024-12239
- EPSS 1.12%
- Veröffentlicht 17.12.2024 03:15:06
- Zuletzt bearbeitet 15.04.2025 15:45:19
The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5 due to insufficient input sanitization and output escaping. This makes...
CVE-2024-43330
- EPSS 0.15%
- Veröffentlicht 18.08.2024 14:15:07
- Zuletzt bearbeitet 15.04.2025 15:10:00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack for Beaver Builder allows Reflected XSS.This issue affects PowerPack for Beaver Builder: from n/a before 2.37.4.
CVE-2024-37409
- EPSS 0.07%
- Veröffentlicht 22.07.2024 09:15:08
- Zuletzt bearbeitet 15.04.2025 15:21:26
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Stored XSS.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3....
CVE-2024-37410
- EPSS 0.93%
- Veröffentlicht 09.07.2024 11:15:13
- Zuletzt bearbeitet 15.04.2025 15:21:26
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Path Traversal.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3.0.3.
CVE-2024-2289
- EPSS 0.15%
- Veröffentlicht 09.04.2024 19:15:30
- Zuletzt bearbeitet 15.04.2025 15:45:34
The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in multiple elements in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user s...
CVE-2022-0176
- EPSS 0.23%
- Veröffentlicht 14.02.2022 12:15:16
- Zuletzt bearbeitet 15.04.2025 15:21:26
The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting