CVE-2022-44626
- EPSS 0.4%
- Veröffentlicht 25.03.2024 12:15:08
- Zuletzt bearbeitet 28.04.2026 19:18:55
Missing Authorization vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.1.20.
CVE-2024-0597
- EPSS 0.5%
- Veröffentlicht 05.02.2024 22:16:02
- Zuletzt bearbeitet 08.04.2026 19:19:12
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 12.3.15 due to insufficient input sanitization and output escaping. This makes it possible for aut...
CVE-2023-50854
- EPSS 0.54%
- Veröffentlicht 28.12.2023 12:15:43
- Zuletzt bearbeitet 28.04.2026 19:22:36
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly Squirrly SEO - Advanced Pack.This issue affects Squirrly SEO - Advanced Pack: from n/a before 2.4.02.
CVE-2022-45065
- EPSS 0.41%
- Veröffentlicht 08.05.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 07:28:42
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 versions.
CVE-2022-38140
- EPSS 0.72%
- Veröffentlicht 28.11.2022 20:15:16
- Zuletzt bearbeitet 21.11.2024 07:15:52
Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
CVE-2021-25019
- EPSS 0.8%
- Veröffentlicht 21.03.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:54:11
The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting