Products

Showing 2 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
smashballoon vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Custom Twitter Feeds < 2.2.3 - Admin+ Stored XSS

Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CWE-77CWE-79Oct 8, 2024
CVSS4.8v3.1EPSS0.407%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to Stored XSS

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

CWE-79Nov 29, 2021
CVSS5.4v3.1EPSS0.654%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX