« Volver al listado

Getlasso

Getlasso Simple Urls: vulnerabilidades y CVE

Getlasso Simple Urls tiene 7 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses1
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-57762Media (5.9)0.24%—2 jul 2026
Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
CVE-2023-40678Media (5.4)0.54%—13 dic 2024
Missing Authorization vulnerability in Andrew Fiebert Simple URLs simple-urls allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through <= 117.
CVE-2023-40674Media (5.4)0.45%—30 nov 2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lasso Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management allows Stored XSS.This issue…
CVE-2023-45606Alta (8.8)0.21%—16 oct 2023
Cross-Site Request Forgery (CSRF) vulnerability in Lasso Simple URLs plugin <= 120 versions.
CVE-2023-40667Media (6.1)0.40%—27 sept 2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions.
CVE-2023-0099Media (6.1)1.7%—13 feb 2023
The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege…
CVE-2023-0098Alta (8.8)0.94%—13 feb 2023
The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable…