Vulnerabilities > Qodeinteractive

DATE CVE VULNERABILITY TITLE RISK
2024-10-23 CVE-2024-9530 Unspecified vulnerability in Qodeinteractive QI Addons for Elementor
The Qi Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.0 via private templates.
network
low complexity
qodeinteractive
4.3
2024-06-07 CVE-2024-4887 Use of Incorrectly-Resolved Name or Reference vulnerability in Qodeinteractive QI Addons for Elementor
The Qi Addons For Elementor plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior' attributes found in the qi_addons_for_elementor_blog_list shortcode.
network
high complexity
qodeinteractive CWE-706
7.5
2024-06-06 CVE-2024-5221 Cross-site Scripting vulnerability in Qodeinteractive QI Blocks
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping.
network
low complexity
qodeinteractive CWE-79
5.4
2024-06-06 CVE-2024-4364 Cross-site Scripting vulnerability in Qodeinteractive QI Addons for Elementor
The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button widgets in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
qodeinteractive CWE-79
5.4
2023-12-29 CVE-2023-47840 Code Injection vulnerability in Qodeinteractive Qode Essential Addons 1.5.2
Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.
network
low complexity
qodeinteractive CWE-94
8.8
2023-11-14 CVE-2023-47680 Cross-site Scripting vulnerability in Qodeinteractive QI Addons for Elementor
Auth.
network
low complexity
qodeinteractive CWE-79
5.4
2023-09-27 CVE-2023-40333 Cross-site Scripting vulnerability in Qodeinteractive Bridge Core 3.0.9
Unauth.
network
low complexity
qodeinteractive CWE-79
6.1
2017-08-23 CVE-2017-13138 Cross-site Scripting vulnerability in Qodeinteractive Bridge
DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript.
network
low complexity
qodeinteractive CWE-79
6.1