Vulnerabilities > Sanskruti

DATE CVE VULNERABILITY TITLE RISK
2021-10-25 CVE-2021-24487 Cross-site Scripting vulnerability in Sanskruti St-Daily-Tip
The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and was also lacking sanitisation as well as escaping before outputting it the page.
network
low complexity
sanskruti CWE-79
8.8