CVE-2025-30867
- EPSS 0.31%
- Veröffentlicht 27.03.2025 10:55:35
- Zuletzt bearbeitet 23.04.2026 15:27:13
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SearchIQ SearchIQ searchiq allows Stored XSS.This issue affects SearchIQ: from n/a through <= 4.7.
CVE-2024-13350
- EPSS 0.22%
- Veröffentlicht 05.03.2025 09:15:09
- Zuletzt bearbeitet 08.04.2026 18:19:59
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on us...
CVE-2024-56229
- EPSS 0.16%
- Veröffentlicht 31.12.2024 10:15:10
- Zuletzt bearbeitet 23.04.2026 15:22:40
Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a through <= 4.6.
CVE-2023-47832
- EPSS 0.4%
- Veröffentlicht 09.12.2024 13:15:31
- Zuletzt bearbeitet 29.04.2026 10:16:25
Missing Authorization vulnerability in SearchIQ SearchIQ searchiq allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through <= 4.4.
CVE-2024-10885
- EPSS 0.28%
- Veröffentlicht 04.12.2024 04:15:04
- Zuletzt bearbeitet 05.06.2025 15:50:23
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on us...
CVE-2024-31259
- EPSS 0.59%
- Veröffentlicht 10.04.2024 16:15:13
- Zuletzt bearbeitet 28.04.2026 19:24:18
Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5.
CVE-2022-0780
- EPSS 0.84%
- Veröffentlicht 18.04.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:22
The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sa...