Vulnerabilities > Gambit
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-01-22 | CVE-2024-12117 | Cross-site Scripting vulnerability in Gambit Stackable The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the Button block in all versions up to, and including, 3.13.11 due to insufficient input sanitization and output escaping. | 5.4 |
2021-09-06 | CVE-2021-24435 | Cross-site Scripting vulnerability in Gambit Titan Framework The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues | 6.1 |