Vulnerabilities > Axelerant

DATE CVE VULNERABILITY TITLE RISK
2024-07-06 CVE-2024-37553 Unspecified vulnerability in Axelerant Testimonials Widget
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Axelerant Testimonials Widget allows Stored XSS.This issue affects Testimonials Widget: from n/a through 4.0.4.
network
low complexity
axelerant
5.4
2024-06-06 CVE-2024-4705 Cross-site Scripting vulnerability in Axelerant Testimonials Widget
The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials shortcode in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
axelerant CWE-79
5.4
2021-03-18 CVE-2021-24136 Cross-site Scripting vulnerability in Axelerant Testimonials Widget
Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL
network
low complexity
axelerant CWE-79
5.4