Vulnerabilities > Qodeinteractive
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-23 | CVE-2024-9530 | Unspecified vulnerability in Qodeinteractive QI Addons for Elementor The Qi Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.0 via private templates. | 4.3 |
2024-06-07 | CVE-2024-4887 | Use of Incorrectly-Resolved Name or Reference vulnerability in Qodeinteractive QI Addons for Elementor The Qi Addons For Elementor plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior' attributes found in the qi_addons_for_elementor_blog_list shortcode. | 7.5 |
2024-06-06 | CVE-2024-5221 | Cross-site Scripting vulnerability in Qodeinteractive QI Blocks The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. | 5.4 |
2024-06-06 | CVE-2024-4364 | Cross-site Scripting vulnerability in Qodeinteractive QI Addons for Elementor The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button widgets in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2023-12-29 | CVE-2023-47840 | Code Injection vulnerability in Qodeinteractive Qode Essential Addons 1.5.2 Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2. | 8.8 |
2023-11-14 | CVE-2023-47680 | Cross-site Scripting vulnerability in Qodeinteractive QI Addons for Elementor Auth. | 5.4 |
2023-09-27 | CVE-2023-40333 | Cross-site Scripting vulnerability in Qodeinteractive Bridge Core 3.0.9 Unauth. | 6.1 |
2017-08-23 | CVE-2017-13138 | Cross-site Scripting vulnerability in Qodeinteractive Bridge DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript. | 6.1 |