Vulnerabilities > Oxilab

DATE CVE VULNERABILITY TITLE RISK
2024-07-22 CVE-2024-37120 Cross-site Scripting vulnerability in Oxilab Responsive Tabs
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Tabs allows Stored XSS.This issue affects Tabs: from n/a through 4.0.6.
network
low complexity
oxilab CWE-79
4.8
2024-07-22 CVE-2024-37121 Cross-site Scripting vulnerability in Oxilab Shortcode Addons
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 Shortcode Addons allows Stored XSS.This issue affects Shortcode Addons: from n/a through 3.2.5.
network
low complexity
oxilab CWE-79
4.8
2024-07-22 CVE-2024-37122 Cross-site Scripting vulnerability in Oxilab Accordions
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Accordions allows Stored XSS.This issue affects Accordions: from n/a through 2.3.5.
network
low complexity
oxilab CWE-79
4.8
2024-07-06 CVE-2024-37546 Cross-site Scripting vulnerability in Oxilab Image Hover Effects for Elementor With Lightbox and Flipbox
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 Image Hover Effects - Caption Hover with Carousel allows Stored XSS.This issue affects Image Hover Effects - Caption Hover with Carousel: from n/a through 3.0.2.
network
low complexity
oxilab CWE-79
5.4
2024-06-06 CVE-2024-5001 Cross-site Scripting vulnerability in Oxilab Image Hover Effects for Elementor With Lightbox and Flipbox
The Image Hover Effects for Elementor with Lightbox and Flipbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_id', 'oxi_addons_f_title_tag', and 'content_description_tag' parameters in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping.
network
low complexity
oxilab CWE-79
5.4
2023-05-04 CVE-2023-25962 Cross-site Scripting vulnerability in Oxilab Accordions
Auth.
network
low complexity
oxilab CWE-79
4.8
2023-03-28 CVE-2022-45831 Cross-site Scripting vulnerability in Oxilab Image Hover Effects for Elementor With Lightbox and Flipbox
Unauth.
network
low complexity
oxilab CWE-79
6.1
2022-12-13 CVE-2022-4207 Unspecified vulnerability in Oxilab Image Hover Effects Ultimate
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping.
network
low complexity
oxilab
5.4
2022-11-18 CVE-2022-42459 Improper Privilege Management vulnerability in Oxilab Image Hover Effects Ultimate
Auth.
network
low complexity
oxilab CWE-269
7.2
2022-11-18 CVE-2022-45082 Cross-site Scripting vulnerability in Oxilab Accordions
Multiple Auth.
network
low complexity
oxilab CWE-79
4.8