CVE-2026-65551
- EPSS 0.23%
- Veröffentlicht 06.08.2026 12:47:56
- Zuletzt bearbeitet 12.08.2026 20:58:37
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7.
CVE-2026-57735
- EPSS 0.18%
- Veröffentlicht 23.07.2026 11:18:09
- Zuletzt bearbeitet 23.07.2026 16:17:27
Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.
CVE-2024-5330
- EPSS 0.26%
- Veröffentlicht 01.08.2024 07:15:02
- Zuletzt bearbeitet 21.11.2024 22:46:26
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it p...
CVE-2024-5331
- EPSS 0.24%
- Veröffentlicht 01.08.2024 07:15:02
- Zuletzt bearbeitet 21.11.2024 23:07:26
The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.
CVE-2024-31390
- EPSS 0.9%
- Veröffentlicht 03.04.2024 12:15:14
- Zuletzt bearbeitet 28.04.2026 19:24:28
: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.