CVE-2025-49863
- EPSS 0.16%
- Veröffentlicht 17.06.2025 15:01:18
- Zuletzt bearbeitet 23.04.2026 15:31:44
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP CodeUs Advanced Sermons advanced-sermons allows Stored XSS.This issue affects Advanced Sermons: from n/a through <= 3.6.
CVE-2024-50458
- EPSS 0.24%
- Veröffentlicht 28.10.2024 18:15:07
- Zuletzt bearbeitet 23.04.2026 15:19:59
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP CodeUs Advanced Sermons advanced-sermons allows Stored XSS.This issue affects Advanced Sermons: from n/a through <= 3.4.
CVE-2024-7599
- EPSS 0.3%
- Veröffentlicht 06.09.2024 14:15:13
- Zuletzt bearbeitet 26.09.2024 16:45:58
The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping. This makes it possible...
CVE-2024-29928
- EPSS 0.4%
- Veröffentlicht 27.03.2024 08:15:40
- Zuletzt bearbeitet 28.04.2026 19:23:53
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Reflected XSS.This issue affects Advanced Sermons: from n/a through 3.1.
CVE-2024-27952
- EPSS 0.4%
- Veröffentlicht 13.03.2024 17:15:48
- Zuletzt bearbeitet 28.04.2026 19:23:34
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Reflected XSS.This issue affects Advanced Sermons: from n/a through 3.2.