Averta

Depicter Slider

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 13.12.2024 15:15:10
  • Zuletzt bearbeitet 13.12.2024 15:15:10

Missing Authorization vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Depicter Slider: from n/a through 1.9.0.

  • EPSS 0.09%
  • Veröffentlicht 06.12.2024 14:15:20
  • Zuletzt bearbeitet 06.12.2024 14:15:20

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘addExtraMimeType’ function in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This ...

  • EPSS 0.08%
  • Veröffentlicht 05.10.2024 15:15:14
  • Zuletzt bearbeitet 07.10.2024 17:47:48

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.2.2.

  • EPSS 0.14%
  • Veröffentlicht 12.08.2024 22:15:10
  • Zuletzt bearbeitet 13.08.2024 12:58:25

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.1.2.

  • EPSS 0.15%
  • Veröffentlicht 16.04.2024 10:15:07
  • Zuletzt bearbeitet 22.05.2025 17:31:51

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output...

  • EPSS 0.06%
  • Veröffentlicht 05.01.2024 02:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:57

The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the 'save'...