Vulnerabilities > Dontdream

DATE CVE VULNERABILITY TITLE RISK
2024-01-31 CVE-2024-22293 Cross-site Scripting vulnerability in Dontdream BP Profile Search
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrea Tarantini BP Profile Search allows Reflected XSS.This issue affects BP Profile Search: from n/a through 5.5.
network
low complexity
dontdream CWE-79
6.1
2023-07-11 CVE-2023-36687 Cross-Site Request Forgery (CSRF) vulnerability in Dontdream Menubar
Cross-Site Request Forgery (CSRF) vulnerability in Andrea Tarantini Menubar plugin <= 5.8.2 versions.
network
low complexity
dontdream CWE-352
6.5