Vulnerabilities > Freehtmldesigns

DATE CVE VULNERABILITY TITLE RISK
2023-12-15 CVE-2023-49190 Cross-site Scripting vulnerability in Freehtmldesigns Site Offline
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows Stored XSS.This issue affects Site Offline Or Coming Soon Or Maintenance Mode: from n/a through 1.5.6.
network
low complexity
freehtmldesigns CWE-79
4.8
2020-12-29 CVE-2020-35773 Cross-Site Request Forgery (CSRF) vulnerability in Freehtmldesigns Site Offline
The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
6.8