Vulnerabilities > Codeless

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-37419 Path Traversal vulnerability in Codeless Cowidgets
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Codeless Cowidgets – Elementor Addons allows Path Traversal.This issue affects Cowidgets – Elementor Addons: from n/a through 1.1.1.
network
low complexity
codeless CWE-22
8.8
2024-06-06 CVE-2024-5179 Path Traversal vulnerability in Codeless Cowidgets Elementor Addons
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 via the 'item_style' and 'style' parameters.
network
low complexity
codeless CWE-22
8.8
2024-06-04 CVE-2024-35782 Cross-site Scripting vulnerability in Codeless Cowidgets - Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through 1.1.1.
network
low complexity
codeless CWE-79
5.4