CVE-2025-49863
- EPSS 0.05%
- Veröffentlicht 17.06.2025 15:01:18
- Zuletzt bearbeitet 17.06.2025 20:50:23
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Stored XSS. This issue affects Advanced Sermons: from n/a through 3.6.
CVE-2024-50458
- EPSS 0.06%
- Veröffentlicht 28.10.2024 18:15:07
- Zuletzt bearbeitet 13.11.2024 19:45:36
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Stored XSS.This issue affects Advanced Sermons: from n/a through 3.4.
CVE-2024-7599
- EPSS 0.1%
- Veröffentlicht 06.09.2024 14:15:13
- Zuletzt bearbeitet 26.09.2024 16:45:58
The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping. This makes it possible...
CVE-2024-29928
- EPSS 0.32%
- Veröffentlicht 27.03.2024 08:15:40
- Zuletzt bearbeitet 18.03.2025 11:33:47
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Reflected XSS.This issue affects Advanced Sermons: from n/a through 3.1.
CVE-2024-27952
- EPSS 0.27%
- Veröffentlicht 13.03.2024 17:15:48
- Zuletzt bearbeitet 18.03.2025 11:07:04
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Reflected XSS.This issue affects Advanced Sermons: from n/a through 3.2.