Vulnerabilities > Hasthemes

DATE CVE VULNERABILITY TITLE RISK
2024-03-27 CVE-2024-30182 Unspecified vulnerability in Hasthemes HT Mega
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through 2.4.3.
network
low complexity
hasthemes
5.4
2024-03-12 CVE-2024-1397 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'titleTag' user supplied attributes.
network
low complexity
hasthemes CWE-79
5.4
2024-03-12 CVE-2024-1421 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping.
network
low complexity
hasthemes CWE-79
5.4
2024-02-29 CVE-2023-51529 Unspecified vulnerability in Hasthemes HT Mega
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.3.
network
low complexity
hasthemes
8.8
2023-12-29 CVE-2023-50901 Unspecified vulnerability in Hasthemes HT Mega
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.8.
network
low complexity
hasthemes
6.1
2023-12-29 CVE-2023-51372 Unspecified vulnerability in Hasthemes Hashbar
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HashBar – WordPress Notification Bar allows Stored XSS.This issue affects HashBar – WordPress Notification Bar: from n/a through 1.4.1.
network
low complexity
hasthemes
4.8
2023-08-30 CVE-2023-32962 Unspecified vulnerability in Hasthemes Wishsuite
Auth.
network
low complexity
hasthemes
4.8
2023-07-17 CVE-2022-47172 Unspecified vulnerability in Hasthemes Woolentor - Woocommerce Elementor Addons + Builder
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.6.2 versions.
network
low complexity
hasthemes
8.8
2023-07-11 CVE-2023-23731 Unspecified vulnerability in Hasthemes Wishsuite
Cross-Site Request Forgery (CSRF) vulnerability in HasTheme WishSuite plugin <= 1.3.3 versions.
network
low complexity
hasthemes
8.8
2023-07-11 CVE-2023-23791 Unspecified vulnerability in Hasthemes HT Menu
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Menu plugin <= 1.2.1 versions.
network
low complexity
hasthemes
8.8