CVE-2025-58027
- EPSS 0.03%
- Veröffentlicht 22.09.2025 18:23:56
- Zuletzt bearbeitet 22.09.2025 21:22:16
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search allows Stored XSS. This issue affects NGG Smart Image Search: from n/a through 3.4.3.
CVE-2025-52832
- EPSS 0.05%
- Veröffentlicht 04.07.2025 11:17:51
- Zuletzt bearbeitet 08.07.2025 16:18:53
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart Image Search allows SQL Injection. This issue affects NGG Smart Image Search: from n/a through 3.4.1.
CVE-2025-47503
- EPSS 0.02%
- Veröffentlicht 07.05.2025 14:19:57
- Zuletzt bearbeitet 08.05.2025 14:39:18
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search allows Stored XSS. This issue affects NGG Smart Image Search: from n/a through 3.3.3.
CVE-2024-13658
- EPSS 0.04%
- Veröffentlicht 12.02.2025 05:15:12
- Zuletzt bearbeitet 24.02.2025 15:49:58
The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping ...