CVE-2026-32399
- EPSS 0.23%
- Veröffentlicht 13.03.2026 11:42:12
- Zuletzt bearbeitet 22.04.2026 21:30:26
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Blind SQL Injection.This issue affects Media LIbrary Assistant: from n/a throug...
CVE-2025-63065
- EPSS 0.36%
- Veröffentlicht 09.12.2025 14:52:34
- Zuletzt bearbeitet 07.10.2026 20:10:01
Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media LIbrary Assistant: from n...
CVE-2025-59590
- EPSS 0.17%
- Veröffentlicht 22.09.2025 19:16:27
- Zuletzt bearbeitet 23.04.2026 15:34:06
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.28...
CVE-2025-7035
- EPSS 0.28%
- Veröffentlicht 16.07.2025 09:22:56
- Zuletzt bearbeitet 23.07.2025 19:14:56
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output esc...
CVE-2025-31627
- EPSS 0.21%
- Veröffentlicht 31.03.2025 13:15:57
- Zuletzt bearbeitet 23.04.2026 15:28:06
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.24...
CVE-2024-11974
- EPSS 0.37%
- Veröffentlicht 04.01.2025 08:15:05
- Zuletzt bearbeitet 31.03.2025 14:00:33
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input...
CVE-2024-51661
- EPSS 1.12%
- Veröffentlicht 04.11.2024 11:15:06
- Zuletzt bearbeitet 23.04.2026 15:20:30
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media LIbrary Assistant: from n/a th...
CVE-2024-6823
- EPSS 1.29%
- Veröffentlicht 13.08.2024 06:15:05
- Zuletzt bearbeitet 07.02.2025 19:13:03
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible f...
CVE-2024-5544
- EPSS 0.36%
- Veröffentlicht 02.07.2024 08:15:06
- Zuletzt bearbeitet 08.04.2026 19:21:57
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for...
CVE-2024-5605
- EPSS 0.58%
- Veröffentlicht 20.06.2024 04:15:18
- Zuletzt bearbeitet 08.04.2026 18:22:09
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied param...