CVE-2026-24626
- EPSS 0.04%
- Veröffentlicht 23.01.2026 14:29:07
- Zuletzt bearbeitet 26.01.2026 15:03:51
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Logo Slider logo-slider-wp allows Stored XSS.This issue affects Logo Slider: from n/a through <= 4.9.0.
CVE-2024-12308
- EPSS 0.08%
- Veröffentlicht 24.02.2025 06:15:10
- Zuletzt bearbeitet 07.05.2025 17:33:46
The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfo...
CVE-2024-10896
- EPSS 0.09%
- Veröffentlicht 28.11.2024 06:15:08
- Zuletzt bearbeitet 15.05.2025 17:35:40
The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting
CVE-2024-10473
- EPSS 0.11%
- Veröffentlicht 28.11.2024 06:15:07
- Zuletzt bearbeitet 15.05.2025 17:39:41
The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing them in pages where the Logo Slider shortcode is embed, which could allow users with a role as low as Author to perform Cross-Site Sc...
CVE-2024-5429
- EPSS 0.32%
- Veröffentlicht 17.10.2024 06:15:02
- Zuletzt bearbeitet 17.05.2025 01:39:09
The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting atta...
CVE-2024-3288
- EPSS 0.79%
- Veröffentlicht 07.06.2024 06:15:10
- Zuletzt bearbeitet 21.11.2024 09:29:19
The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting atta...
CVE-2022-4664
- EPSS 0.25%
- Veröffentlicht 06.02.2023 20:15:11
- Zuletzt bearbeitet 25.03.2025 21:15:38
The Logo Slider WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfor...