Vulnerabilities (CVE)

Filtered by vendor Link Library Project Subscribe
Filtered by product Link Library
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25091 1 Link Library Project 1 Link Library 2022-02-04 4.3 MEDIUM 6.1 MEDIUM
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2021-25092 1 Link Library Project 1 Link Library 2022-02-04 4.3 MEDIUM 6.5 MEDIUM
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack