CVE-2022-4699
- EPSS 0.2%
- Veröffentlicht 30.01.2023 21:15:11
- Zuletzt bearbeitet 21.04.2025 13:58:19
The MediaElement.js WordPress plugin through 4.2.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting...
CVE-2016-4567
- EPSS 3.88%
- Veröffentlicht 22.05.2016 01:59:31
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction pa...
CVE-2013-1967
- EPSS 0.57%
- Veröffentlicht 05.02.2014 15:10:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file par...