Vulnerabilities > Sinaextra

DATE CVE VULNERABILITY TITLE RISK
2024-03-27 CVE-2024-29935 Unspecified vulnerability in Sinaextra Sina Extension for Elementor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through 3.5.0.
network
low complexity
sinaextra
5.4
2021-05-05 CVE-2021-24269 Cross-site Scripting vulnerability in Sinaextra Sina Extension for Elementor
The “Sina Extension for Elementor” WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
network
low complexity
sinaextra CWE-79
5.4
2019-08-30 CVE-2019-15839 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Sinaextra Sina Extension for Elementor
The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
network
low complexity
sinaextra CWE-829
7.5