Vulnerabilities > Freehtmldesigns

DATE CVE VULNERABILITY TITLE RISK
2023-12-15 CVE-2023-49190 Cross-site Scripting vulnerability in Freehtmldesigns Site Offline
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows Stored XSS.This issue affects Site Offline Or Coming Soon Or Maintenance Mode: from n/a through 1.5.6.
network
low complexity
freehtmldesigns CWE-79
4.8
2022-09-19 CVE-2022-1580 Authorization Bypass Through User-Controlled Key vulnerability in Freehtmldesigns Site Offline
The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords.
network
low complexity
freehtmldesigns CWE-639
4.3
2020-12-29 CVE-2020-35773 Cross-Site Request Forgery (CSRF) vulnerability in Freehtmldesigns Site Offline
The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
network
low complexity
freehtmldesigns CWE-352
8.8