CVE-2023-6880
- EPSS 0.42%
- Veröffentlicht 13.03.2024 16:15:09
- Zuletzt bearbeitet 08.04.2026 18:18:44
The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and includin...
CVE-2020-36722
- EPSS 0.73%
- Veröffentlicht 07.06.2023 02:15:12
- Zuletzt bearbeitet 08.04.2026 19:17:34
The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts tha...
CVE-2022-2516
- EPSS 0.53%
- Veröffentlicht 06.09.2022 18:15:14
- Zuletzt bearbeitet 21.11.2024 07:01:09
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it pos...
CVE-2022-2430
- EPSS 0.53%
- Veröffentlicht 06.09.2022 18:15:13
- Zuletzt bearbeitet 21.11.2024 07:00:58
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possib...