Vulnerabilities > Averta

DATE CVE VULNERABILITY TITLE RISK
2024-08-29 CVE-2024-1384 Cross-site Scripting vulnerability in Averta Auxinportfolio
The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_recent_portfolios_grid' shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
averta CWE-79
5.4
2024-08-21 CVE-2024-6339 Cross-site Scripting vulnerability in Averta Phlox
The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions up to, and including, 5.16.4 due to insufficient input sanitization and output escaping.
network
low complexity
averta CWE-79
6.1
2024-07-16 CVE-2024-3587 Cross-site Scripting vulnerability in Averta Auxinportfolio
The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Portfolios Widget in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
averta CWE-79
5.4
2024-06-18 CVE-2024-4375 Cross-site Scripting vulnerability in Averta Master Slider 3.2.7/3.5.1
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'css_id' user supplied attribute.
network
low complexity
averta CWE-79
5.4
2024-01-05 CVE-2023-6493 Cross-Site Request Forgery (CSRF) vulnerability in Averta Depicter Slider
The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6.
network
low complexity
averta CWE-352
4.3
2023-12-20 CVE-2023-47507 Deserialization of Untrusted Data vulnerability in Averta Master Slider PRO 3.6.5
Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5.
network
low complexity
averta CWE-502
critical
9.8
2023-12-14 CVE-2023-50368 Cross-site Scripting vulnerability in Averta Shortcodes and Extra Features for Phlox Theme
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Shortcodes and extra features for Phlox theme allows Stored XSS.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.2.
network
low complexity
averta CWE-79
5.4
2023-11-16 CVE-2023-47508 Cross-site Scripting vulnerability in Averta Master Slider 3.2.7/3.5.1
Unauth.
network
low complexity
averta CWE-79
6.1
2022-12-12 CVE-2022-3359 Unspecified vulnerability in Averta Shortcodes and Extra Features for Phlox Theme
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
network
low complexity
averta
8.8
2022-07-11 CVE-2022-1910 Cross-site Scripting vulnerability in Averta Shortcodes and Extra Features for Phlox Theme
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
network
averta CWE-79
4.3