Vulnerabilities > Gingerplugins

DATE CVE VULNERABILITY TITLE RISK
2023-12-29 CVE-2023-51361 Cross-site Scripting vulnerability in Gingerplugins Sticky Chat Widget
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ginger Plugins Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button allows Stored XSS.This issue affects Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button: from n/a through 1.1.8.
network
low complexity
gingerplugins CWE-79
4.8