CVE-2026-104387
- EPSS 0.32%
- Veröffentlicht 06.10.2026 08:35:13
- Zuletzt bearbeitet 06.10.2026 15:04:25
Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.
CVE-2026-97319
- EPSS 0.15%
- Veröffentlicht 27.09.2026 06:00:23
- Zuletzt bearbeitet 28.09.2026 15:17:39
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Script...
CVE-2026-32351
- EPSS 0.17%
- Veröffentlicht 13.03.2026 11:41:59
- Zuletzt bearbeitet 22.04.2026 21:30:26
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows Stored XSS.This issue affects PowerPress Podcasting: from n/a through <= 11.15.13.
CVE-2026-23798
- EPSS 0.48%
- Veröffentlicht 05.03.2026 06:16:22
- Zuletzt bearbeitet 22.04.2026 21:26:58
Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: from n/a through <= 11.15.10.
CVE-2025-64201
- EPSS 0.12%
- Veröffentlicht 29.10.2025 08:38:06
- Zuletzt bearbeitet 08.10.2026 11:10:00
Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12.
CVE-2024-9230
- EPSS 0.25%
- Veröffentlicht 14.04.2025 06:00:04
- Zuletzt bearbeitet 29.04.2025 20:33:55
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow author and above users to perform Stored Cross-Site Scripting attacks