CVE-2014-5345
Disqus Comment System < 2.75 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.
Exploits (1)
References (5)
Scores
EPSS
0.0229
EPSS Percentile
84.8%
Details
CWE
CWE-79
Status
published
Products (32)
disqus/disqus_comment_system
2.40
disqus/disqus_comment_system
2.41
disqus/disqus_comment_system
2.42
disqus/disqus_comment_system
2.43
disqus/disqus_comment_system
2.44
disqus/disqus_comment_system
2.45
disqus/disqus_comment_system
2.46
disqus/disqus_comment_system
2.47
disqus/disqus_comment_system
2.48
disqus/disqus_comment_system
2.49
... and 22 more
Published
Aug 19, 2014
Tracked Since
Feb 18, 2026