« Volver al listado

Tagdiv

Tagdiv Newspaper: vulnerabilidades y CVE

Tagdiv Newspaper tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-3815Media (4.8)0.28%—15 jun 2024
The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output…
CVE-2022-2627Media (6.1)1.0%—31 oct 2022
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.
CVE-2022-2167Media (6.1)0.58%—31 oct 2022
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting
CVE-2021-3135Media (6.1)0.83%—19 jul 2021
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
CVE-2016-10972Crítica (9.8)9.3%—16 sept 2019
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
CVE-2017-18634Crítica (9.8)2.2%—16 sept 2019
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.

Otros productos de Tagdiv