Vulnerabilities > 23Systems

DATE CVE VULNERABILITY TITLE RISK
2019-08-09 CVE-2016-10865 Cross-Site Request Forgery (CSRF) vulnerability in 23Systems Lightbox Plus Colorbox 2.7.2
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
network
low complexity
23systems CWE-352
6.1