CVE-2025-8607
- EPSS 0.03%
- Veröffentlicht 21.08.2025 05:28:14
- Zuletzt bearbeitet 22.08.2025 18:09:17
The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block's attributes in all versions up to, and including, 1.6.0 due to insufficient inpu...
CVE-2024-13675
- EPSS 0.07%
- Veröffentlicht 08.03.2025 12:15:35
- Zuletzt bearbeitet 11.03.2025 21:27:49
The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Icon List" Block in all versions up to, and including, 1.5.0 due to insufficient input sanitization and o...
CVE-2024-38684
- EPSS 0.09%
- Veröffentlicht 20.07.2024 08:15:08
- Zuletzt bearbeitet 21.11.2024 09:26:37
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FunnelKit SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) allows Stored XSS.This issue affects SlingBlocks – Gutenberg Bloc...