Vulnerabilities > Etsy Shop Project

DATE CVE VULNERABILITY TITLE RISK
2023-11-09 CVE-2023-25975 Cross-Site Request Forgery (CSRF) vulnerability in Etsy Shop Project Etsy Shop
Cross-Site Request Forgery (CSRF) vulnerability in Frédéric Sheedy Etsy Shop plugin <= 3.0.3 versions.
network
low complexity
etsy-shop-project CWE-352
8.8
2023-10-12 CVE-2023-5470 Unspecified vulnerability in Etsy Shop Project Etsy Shop
The Etsy Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etsy-shop' shortcode in versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
etsy-shop-project
5.4