CVE-2022-4699
- EPSS 0.3%
- Veröffentlicht 30.01.2023 21:15:11
- Zuletzt bearbeitet 21.04.2025 13:58:19
The MediaElement.js WordPress plugin through 4.2.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting...
CVE-2016-4567
- EPSS 4.16%
- Veröffentlicht 22.05.2016 01:59:31
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction pa...
CVE-2013-1967
- EPSS 0.57%
- Veröffentlicht 05.02.2014 15:10:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file par...