Vulnerabilities > Podlove > Podlove Podcast Publisher > 3.5.6

DATE CVE VULNERABILITY TITLE RISK
2025-03-06 CVE-2025-1383 Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podcast Publisher
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2.
network
low complexity
podlove CWE-352
4.3
2025-01-18 CVE-2025-0554 Cross-site Scripting vulnerability in Podlove Podcast Publisher
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value in version <= 4.1.25 due to insufficient input sanitization and output escaping.
network
high complexity
podlove CWE-79
4.0
2024-11-14 CVE-2024-52393 Code Injection vulnerability in Podlove Podcast Publisher
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.15.
network
low complexity
podlove CWE-94
7.2
2024-10-31 CVE-2024-43984 Unspecified vulnerability in Podlove Podcast Publisher
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
network
low complexity
podlove
8.8
2024-09-18 CVE-2024-43983 Cross-site Scripting vulnerability in Podlove Podcast Publisher
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Stored XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
network
low complexity
podlove CWE-79
5.4
2024-06-11 CVE-2024-32143 Unspecified vulnerability in Podlove Podcast Publisher
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0.
network
low complexity
podlove
8.8
2024-05-14 CVE-2024-32712 Missing Authorization vulnerability in Podlove Podcast Publisher
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.
network
low complexity
podlove CWE-862
4.3
2024-04-24 CVE-2024-32812 Unspecified vulnerability in Podlove Podcast Publisher
Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.11.
network
low complexity
podlove
5.4
2024-04-15 CVE-2024-32139 Unspecified vulnerability in Podlove Podcast Publisher
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.12.
network
low complexity
podlove
8.8
2024-03-27 CVE-2024-29915 Unspecified vulnerability in Podlove Podcast Publisher
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Reflected XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.0.9.
network
low complexity
podlove
6.1