CVE-2025-30867
- EPSS 0.13%
- Veröffentlicht 27.03.2025 10:55:35
- Zuletzt bearbeitet 09.06.2025 19:01:19
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SearchIQ SearchIQ allows Stored XSS. This issue affects SearchIQ: from n/a through 4.7.
CVE-2024-13350
- EPSS 0.09%
- Veröffentlicht 05.03.2025 09:15:09
- Zuletzt bearbeitet 26.05.2025 01:54:31
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on us...
CVE-2024-56229
- EPSS 0.12%
- Veröffentlicht 31.12.2024 10:15:10
- Zuletzt bearbeitet 05.06.2025 20:59:43
Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6.
CVE-2023-47832
- EPSS 0.37%
- Veröffentlicht 09.12.2024 13:15:31
- Zuletzt bearbeitet 09.06.2025 20:39:14
Missing Authorization vulnerability in searchiq SearchIQ allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through 4.4.
CVE-2024-10885
- EPSS 0.17%
- Veröffentlicht 04.12.2024 04:15:04
- Zuletzt bearbeitet 05.06.2025 15:50:23
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on us...
CVE-2024-31259
- EPSS 1.69%
- Veröffentlicht 10.04.2024 16:15:13
- Zuletzt bearbeitet 08.04.2025 14:43:39
Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5.
CVE-2022-0780
- EPSS 1.14%
- Veröffentlicht 18.04.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:22
The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sa...