CVE-2026-39517
- EPSS 0.03%
- Veröffentlicht 08.04.2026 08:30:15
- Zuletzt bearbeitet 10.04.2026 18:16:44
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.6.
CVE-2025-69033
- EPSS 0.05%
- Veröffentlicht 30.12.2025 10:47:57
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.3.
CVE-2023-5291
- EPSS 0.09%
- Veröffentlicht 04.10.2023 02:15:10
- Zuletzt bearbeitet 08.04.2026 19:18:45
The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This make...
CVE-2023-5295
- EPSS 0.08%
- Veröffentlicht 30.09.2023 03:15:09
- Zuletzt bearbeitet 08.04.2026 18:18:25
The Comments by Startbit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. Thi...