Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.1
CVE-2026-17577
- EPSS 0.27%
- Veröffentlicht 25.09.2026 07:40:25
- Zuletzt bearbeitet 25.09.2026 13:08:08
The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uri' (and 'host') parameters in versions up to, and including, 4.7.42. The ssl_zen_messages::getMessages() function builds the 'token_missmatch' message using b...
7.1
CVE-2026-28569
- EPSS 0.18%
- Veröffentlicht 18.08.2026 13:59:05
- Zuletzt bearbeitet 20.08.2026 12:49:04
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
6.5
CVE-2024-1076
- EPSS 0.41%
- Veröffentlicht 08.05.2024 06:15:06
- Zuletzt bearbeitet 17.06.2025 18:53:43
The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacke...
1