Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.5
CVE-2025-26742
- EPSS 0.07%
- Veröffentlicht 25.03.2025 14:37:51
- Zuletzt bearbeitet 27.03.2025 16:45:46
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through 1.0.0.35.
5.4
CVE-2024-3236
- EPSS 0.22%
- Veröffentlicht 17.06.2024 06:15:08
- Zuletzt bearbeitet 13.05.2025 01:40:22
The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.
4.3
CVE-2022-2224
- EPSS 0.14%
- Veröffentlicht 18.07.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:34
The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed. This make it poss...
1