CVE-2025-48107
- EPSS 0.05%
- Veröffentlicht 26.09.2025 09:15:32
- Zuletzt bearbeitet 26.09.2025 14:32:19
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undsgn Uncode allows Reflected XSS. This issue affects Uncode: from n/a through n/a.
CVE-2024-13689
- EPSS 0.31%
- Veröffentlicht 18.02.2025 15:15:15
- Zuletzt bearbeitet 18.02.2025 15:15:15
The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running ...
CVE-2024-13667
- EPSS 0.08%
- Veröffentlicht 18.02.2025 11:15:11
- Zuletzt bearbeitet 21.02.2025 14:23:07
The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authe...
CVE-2024-13681
- EPSS 0.53%
- Veröffentlicht 18.02.2025 11:15:11
- Zuletzt bearbeitet 21.02.2025 14:22:38
The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for unauthenticated attackers to ...
CVE-2024-13691
- EPSS 0.15%
- Veröffentlicht 18.02.2025 11:15:11
- Zuletzt bearbeitet 21.02.2025 14:22:06
The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subs...
CVE-2023-51515
- EPSS 0.19%
- Veröffentlicht 12.04.2024 15:15:22
- Zuletzt bearbeitet 21.11.2024 08:38:17
Missing Authorization vulnerability in Undsgn Uncode Core allows Privilege Escalation.This issue affects Uncode Core: from n/a through 2.8.8.
CVE-2023-51501
- EPSS 0.08%
- Veröffentlicht 28.12.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 08:38:15
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Undsgn Uncode - Creative & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Uncode - Creative & WooCommerce WordPress Theme: from...