Vulnerabilities > Scriptsbundle

DATE CVE VULNERABILITY TITLE RISK
2025-02-08 CVE-2025-0169 Cross-site Scripting vulnerability in Scriptsbundle DWT Listing
The DWT - Directory & Listing WordPress Theme is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
scriptsbundle CWE-79
5.4
2025-01-22 CVE-2024-12857 Missing Authentication for Critical Function vulnerability in Scriptsbundle Adforest
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8.
network
low complexity
scriptsbundle CWE-306
critical
9.8