CVE-2024-8854
- EPSS 0.05%
- Veröffentlicht 15.05.2025 20:16:00
- Zuletzt bearbeitet 04.06.2025 16:31:17
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall...
CVE-2024-8851
- EPSS 0.05%
- Veröffentlicht 15.05.2025 20:15:59
- Zuletzt bearbeitet 04.06.2025 16:31:03
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall...
CVE-2024-24874
- EPSS 0.16%
- Veröffentlicht 17.05.2024 09:15:24
- Zuletzt bearbeitet 21.11.2024 08:59:53
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71.
CVE-2024-24873
- EPSS 0.21%
- Veröffentlicht 17.05.2024 09:15:23
- Zuletzt bearbeitet 21.11.2024 08:59:53
: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.
CVE-2014-125091
- EPSS 0.14%
- Veröffentlicht 04.03.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 02:03:46
A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the argument lu leads to sql inject...
CVE-2014-10395
- EPSS 0.19%
- Veröffentlicht 27.08.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 02:03:31
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
CVE-2015-9346
- EPSS 0.19%
- Veröffentlicht 27.08.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 02:40:24
The cp-polls plugin before 1.0.5 for WordPress has XSS.