Vulnerabilities > Arnoldgoodway

DATE CVE VULNERABILITY TITLE RISK
2024-09-13 CVE-2024-5869 Cross-site Scripting vulnerability in Arnoldgoodway Neighborly
The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping.
network
low complexity
arnoldgoodway CWE-79
5.4
2024-09-13 CVE-2024-5870 Cross-site Scripting vulnerability in Arnoldgoodway Tweaker5
The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping.
network
low complexity
arnoldgoodway CWE-79
5.4