Vulnerabilities > 10Up > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-26 CVE-2024-43116 Cross-Site Request Forgery (CSRF) vulnerability in 10Up Simple Local Avatars
Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.
network
low complexity
10up CWE-352
8.8
2019-11-11 CVE-2019-18855 Unspecified vulnerability in 10Up Safe SVG
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
network
low complexity
10up
7.5
2019-11-11 CVE-2019-18854 Uncontrolled Recursion vulnerability in 10Up Safe SVG
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ...
network
low complexity
10up CWE-674
7.5