Filtered by vendor Wpmanageninja
Subscriptions
Total
24 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-24900 | 1 Wpmanageninja | 1 Ninja Tables | 2024-11-21 | 4.8 Medium |
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||
CVE-2021-24528 | 1 Wpmanageninja | 1 Fluentsmtp | 2024-11-21 | 5.4 Medium |
The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to a stored cross site scripting (XSS) vulnerability. Only users with roles capable of managing plugins can modify the plugin's settings. | ||||
CVE-2024-47302 | 1 Wpmanageninja | 1 Fluent Support | 2024-11-19 | 5.3 Medium |
Missing Authorization vulnerability in WPManageNinja LLC Fluent Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through 1.8.0. | ||||
CVE-2024-7304 | 1 Wpmanageninja | 1 Ninja Tables | 2024-09-12 | 6.4 Medium |
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. |