Vulnerabilities (CVE)

Filtered by vendor Shooflysolutions Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-5137 1 Shooflysolutions 1 Simply Excerpts 2023-12-07 N/A 4.8 MEDIUM
The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).
CVE-2023-32598 1 Shooflysolutions 1 Featured Image Pro Post Grid 2023-08-28 N/A 6.1 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in A. R. Jones Featured Image Pro Post Grid plugin <= 5.14 versions.