Vulnerabilities > Codeless

DATE CVE VULNERABILITY TITLE RISK
2024-11-09 CVE-2024-10779 Unspecified vulnerability in Codeless Cowidgets Elementor Addons
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.0 via the 'ce_template' shortcode due to insufficient restrictions on which posts can be included.
network
low complexity
codeless
4.3
2024-11-09 CVE-2024-8960 Cross-site Scripting vulnerability in Codeless Cowidgets Elementor Addons
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping.
network
low complexity
codeless CWE-79
5.4
2024-07-09 CVE-2024-37419 Unspecified vulnerability in Codeless Cowidgets
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Codeless Cowidgets – Elementor Addons allows Path Traversal.This issue affects Cowidgets – Elementor Addons: from n/a through 1.1.1.
network
low complexity
codeless
8.8
2024-06-04 CVE-2024-35782 Unspecified vulnerability in Codeless Cowidgets - Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through 1.1.1.
network
low complexity
codeless
5.4
2024-06-04 CVE-2024-4697 Cross-site Scripting vulnerability in Codeless Cowidgets Elementor Addons
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’ parameter in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping.
network
low complexity
codeless CWE-79
5.4