Vulnerabilities > Cminds > Tooltip Glossary > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-10-04 CVE-2021-24678 Cross-site Scripting vulnerability in Cminds Tooltip Glossary
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks
network
low complexity
cminds CWE-79
5.4
2016-10-10 CVE-2016-1000132 Cross-site Scripting vulnerability in Cminds Tooltip Glossary
Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8
network
low complexity
cminds CWE-79
6.1