Tablepress

Tablepress

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 23.05.2025 08:23:39
  • Zuletzt bearbeitet 11.07.2025 19:41:21

The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data-s-content-padding', 'data-s-title', and 'data-footer' data-attributes in all versions up to, and including, 3.1.2 due to insuffic...

  • EPSS 0.07%
  • Veröffentlicht 27.03.2025 05:22:30
  • Zuletzt bearbeitet 08.08.2025 19:18:08

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘table-name’ parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. Th...

  • EPSS 0.29%
  • Veröffentlicht 12.10.2024 09:15:03
  • Zuletzt bearbeitet 09.08.2025 01:40:09

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This m...

  • EPSS 0.84%
  • Veröffentlicht 07.06.2024 06:15:11
  • Zuletzt bearbeitet 21.11.2024 09:42:41

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 via the get_files_to_import() function. This makes it possible for authenticated attackers, wit...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 30.01.2024 17:15:11
  • Zuletzt bearbeitet 21.11.2024 08:58:30

TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintend...

  • EPSS 2.88%
  • Veröffentlicht 09.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:38:10

The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.

  • EPSS 0.3%
  • Veröffentlicht 17.11.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.