Vulnerabilities > Cminds > Tooltip Glossary > 3.0.1

DATE CVE VULNERABILITY TITLE RISK
2021-10-04 CVE-2021-24678 Cross-site Scripting vulnerability in Cminds Tooltip Glossary
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks
network
cminds CWE-79
3.5
2016-10-10 CVE-2016-1000132 Cross-site Scripting vulnerability in Cminds Tooltip Glossary
Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8
network
cminds CWE-79
4.3