CVE-2025-5096
- EPSS 0.11%
- Veröffentlicht 23.05.2025 08:23:39
- Zuletzt bearbeitet 11.07.2025 19:41:21
The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data-s-content-padding', 'data-s-title', and 'data-footer' data-attributes in all versions up to, and including, 3.1.2 due to insuffic...
CVE-2025-2685
- EPSS 0.07%
- Veröffentlicht 27.03.2025 05:22:30
- Zuletzt bearbeitet 08.08.2025 19:18:08
The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘table-name’ parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. Th...
CVE-2024-9595
- EPSS 0.29%
- Veröffentlicht 12.10.2024 09:15:03
- Zuletzt bearbeitet 09.08.2025 01:40:09
The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This m...
CVE-2024-4354
- EPSS 0.84%
- Veröffentlicht 07.06.2024 06:15:11
- Zuletzt bearbeitet 21.11.2024 09:42:41
The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 via the get_files_to_import() function. This makes it possible for authenticated attackers, wit...
CVE-2024-23825
- EPSS 0.4%
- Veröffentlicht 30.01.2024 17:15:11
- Zuletzt bearbeitet 21.11.2024 08:58:30
TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintend...
CVE-2019-20180
- EPSS 2.88%
- Veröffentlicht 09.01.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:38:10
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.
CVE-2017-10889
- EPSS 0.3%
- Veröffentlicht 17.11.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.