Vulnerabilities > Lenderd

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2022-45357 Improper Neutralization of Formula Elements in a CSV File vulnerability in Lenderd 1003 Mortgage Application
Improper Neutralization of Formula Elements in a CSV File vulnerability in Lenderd 1003 Mortgage Application.This issue affects 1003 Mortgage Application: from n/a through 1.75.
network
low complexity
lenderd CWE-1236
critical
9.8
2022-02-14 CVE-2021-24904 Cross-site Scripting vulnerability in Lenderd Mortgage Calculators WP
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
network
low complexity
lenderd CWE-79
4.8