Themepunch

Slider Revolution

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 01.10.2024 07:15:06
  • Zuletzt bearbeitet 13.11.2024 18:06:00

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

  • EPSS 0.11%
  • Veröffentlicht 21.07.2024 23:15:02
  • Zuletzt bearbeitet 21.11.2024 09:23:51

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.7.13.

  • EPSS 0.17%
  • Veröffentlicht 19.06.2024 15:15:59
  • Zuletzt bearbeitet 21.11.2024 09:18:40

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects Slider Revolution: from n/a before 6.7.11.

  • EPSS 0.5%
  • Veröffentlicht 19.06.2024 15:15:59
  • Zuletzt bearbeitet 21.11.2024 09:18:41

Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.

  • EPSS 0.31%
  • Veröffentlicht 04.06.2024 10:15:12
  • Zuletzt bearbeitet 27.01.2025 18:22:19

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' di...

  • EPSS 0.33%
  • Veröffentlicht 04.06.2024 09:15:09
  • Zuletzt bearbeitet 27.01.2025 18:21:15

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'cl...

  • EPSS 0.21%
  • Veröffentlicht 02.05.2024 17:15:34
  • Zuletzt bearbeitet 03.02.2025 19:37:22

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Exploit
  • EPSS 15.79%
  • Veröffentlicht 08.01.2024 19:15:10
  • Zuletzt bearbeitet 03.06.2025 15:15:51

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.

  • EPSS 0.18%
  • Veröffentlicht 20.12.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 08:30:48

Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.

  • EPSS 0.09%
  • Veröffentlicht 20.11.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:30:47

Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14.