CVE-2026-32351
- EPSS 0.03%
- Veröffentlicht 13.03.2026 11:41:59
- Zuletzt bearbeitet 16.03.2026 15:16:22
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows Stored XSS.This issue affects PowerPress Podcasting: from n/a through <= 11.15.13.
CVE-2026-23798
- EPSS 0.06%
- Veröffentlicht 05.03.2026 06:16:22
- Zuletzt bearbeitet 09.03.2026 15:15:56
Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: from n/a through <= 11.15.10.
CVE-2025-64201
- EPSS 0.01%
- Veröffentlicht 29.10.2025 08:38:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12.
CVE-2024-9230
- EPSS 0.18%
- Veröffentlicht 14.04.2025 06:00:04
- Zuletzt bearbeitet 29.04.2025 20:33:55
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow author and above users to perform Stored Cross-Site Scripting attacks