Majeedraza
Majeedraza Carousel Slider: vulnerabilidades y CVE
Majeedraza Carousel Slider tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-41848 | Media (5.3) | 0.56% | — | 13 dic 2024 | Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2. |
| CVE-2024-6850 | Media (4.8) | 0.34% | — | 13 sept 2024 | The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when… |
| CVE-2024-45270 | Media (4.3) | 0.23% | — | 2 sept 2024 | WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled,… |
| CVE-2024-45269 | Media (4.3) | 0.27% | — | 2 sept 2024 | WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin… |
| CVE-2024-4372 | Media (5.4) | 0.40% | — | 21 may 2024 | The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks |
| CVE-2024-3703 | Media (4.7) | 0.50% | — | 3 may 2024 | The Carousel Slider WordPress plugin before 2.2.10 does not validate and escape some of its Slide options before outputting them back in the page/post where the related Slide shortcode is embed, which could allow users… |
| CVE-2024-1712 | Media (4.7) | 0.48% | — | 15 abr 2024 | The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |