CVE-2026-28178
- EPSS 0.16%
- Veröffentlicht 06.08.2026 14:27:15
- Zuletzt bearbeitet 12.08.2026 20:58:37
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-15644
- EPSS 0.21%
- Veröffentlicht 01.08.2026 09:16:59
- Zuletzt bearbeitet 12.08.2026 21:00:37
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. T...
CVE-2026-15649
- EPSS 0.2%
- Veröffentlicht 01.08.2026 07:49:53
- Zuletzt bearbeitet 12.08.2026 21:00:37
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This mak...
CVE-2026-15645
- EPSS 0.21%
- Veröffentlicht 01.08.2026 07:49:47
- Zuletzt bearbeitet 12.08.2026 21:00:37
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. Thi...
CVE-2024-2458
- EPSS 0.32%
- Veröffentlicht 06.04.2024 08:15:07
- Zuletzt bearbeitet 08.04.2026 19:21:07
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping on use...