Kaizencoders

Url Shortify

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 19.02.2026 08:27:01
  • Zuletzt bearbeitet 19.02.2026 21:18:31

Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Forgery.This issue affects URL Shortify: from n/a through <= 1.12.3.

  • EPSS 0.03%
  • Veröffentlicht 18.02.2026 04:35:45
  • Zuletzt bearbeitet 18.02.2026 17:51:53

The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthent...

  • EPSS 0.17%
  • Veröffentlicht 04.04.2025 16:15:21
  • Zuletzt bearbeitet 07.04.2025 14:18:15

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders URL Shortify allows Stored XSS. This issue affects URL Shortify: from n/a through 1.10.4.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 06.11.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:42:06

The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall...

Exploit
  • EPSS 34.97%
  • Veröffentlicht 11.09.2023 20:15:11
  • Zuletzt bearbeitet 02.05.2025 18:15:25

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the crea...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 10.07.2023 16:15:55
  • Zuletzt bearbeitet 21.11.2024 08:16:31

The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallow...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 29.11.2021 09:15:07
  • Zuletzt bearbeitet 30.01.2026 16:52:02

The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.