Vektor-inc
Vektor-inc VK ALL IN ONE Expansion Unit: vulnerabilidades y CVE
Vektor-inc VK ALL IN ONE Expansion Unit tiene 12 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-39483 | Media (6.5) | 0.22% | — | 8 abr 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.This issue affects VK… |
| CVE-2025-11737 | Media (6.4) | 0.20% | — | 18 feb 2026 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns_title' parameter in all versions up to, and including, 9.112.3 due to insufficient input… |
| CVE-2025-11267 | Media (6.4) | 0.23% | — | 18 nov 2025 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_css' parameter in all versions up to, and including, 9.112.1. This is due to insufficient input… |
| CVE-2025-11265 | Media (6.4) | 0.23% | — | 18 nov 2025 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta_url' and 'vkExUnit_cta_button_text' parameters in all versions up to, and including, 9.112.1. This… |
| CVE-2024-52268 | Media (4.8) | 0.30% | — | 13 nov 2024 | Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is… |
| CVE-2024-37956 | Media (5.4) | 0.31% | — | 20 jul 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vektor,Inc. VK All in One Expansion Unit allows Stored XSS.This issue affects VK All in One Expansion Unit:… |
| CVE-2024-2093 | Media (5.3) | 0.68% | — | 9 abr 2024 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 via social meta tags. This makes it possible for unauthenticated… |
| CVE-2024-2170 | Media (5.4) | 0.34% | — | 26 mar 2024 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page index widget in all versions up to, and including, 9.96.0.1 due to insufficient input sanitization… |
| CVE-2023-28367 | Media (5.4) | 0.61% | — | 23 may 2023 | Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script. |
| CVE-2023-27926 | Media (5.4) | 0.61% | — | 23 may 2023 | Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script. |
| CVE-2023-0937 | Media (6.1) | 0.52% | — | 20 mar 2023 | The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in… |
| CVE-2023-0230 | Media (5.4) | 0.56% | — | 27 feb 2023 | The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with… |