CVE-2025-5289
- EPSS 0.05%
- Veröffentlicht 21.06.2025 11:15:35
- Zuletzt bearbeitet 09.07.2025 19:22:16
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ and 'mode' parameters in all versions up to, and including, 1.16.15 due to insufficient inpu...
CVE-2024-43152
- EPSS 0.07%
- Veröffentlicht 12.08.2024 22:15:09
- Zuletzt bearbeitet 29.01.2025 16:19:05
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery allows Stored XSS.This issue affects 3D FlipBook – PDF Flipbook Viewer,...
CVE-2024-3883
- EPSS 0.18%
- Veröffentlicht 02.05.2024 09:15:07
- Zuletzt bearbeitet 03.02.2025 20:24:02
The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all versions up to, and including, 1.15.4 due to insufficient input sanitization and output escaping. This makes it possible for authentic...
CVE-2024-1081
- EPSS 0.08%
- Veröffentlicht 21.02.2024 07:15:53
- Zuletzt bearbeitet 04.02.2025 20:59:54
The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bookmark feature in all versions up to, and including, 1.15.3 due to insufficient input sanitization and output escaping. This...
CVE-2023-6776
- EPSS 0.17%
- Veröffentlicht 11.01.2024 09:15:51
- Zuletzt bearbeitet 21.11.2024 08:44:32
The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all versions up to, and including, 1.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authe...
CVE-2022-4453
- EPSS 0.17%
- Veröffentlicht 16.01.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 07:35:17
The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting att...
CVE-2022-0423
- EPSS 0.29%
- Veröffentlicht 21.03.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:38:35
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting paylo...