Vulnerabilities > Sktthemes > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-02-12 CVE-2024-13665 Cross-site Scripting vulnerability in Sktthemes Admire Extra
The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
sktthemes CWE-79
5.4
2024-09-18 CVE-2024-43995 Cross-site Scripting vulnerability in Sktthemes Posterity
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sonalsinha21 Posterity allows Stored XSS.This issue affects Posterity: from n/a through 3.6.
network
low complexity
sktthemes CWE-79
5.4
2024-09-17 CVE-2024-44007 Cross-site Scripting vulnerability in Sktthemes SKT Templates
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Templates – Elementor & Gutenberg templates allows Reflected XSS.This issue affects SKT Templates – Elementor & Gutenberg templates: from n/a through 6.14.
network
low complexity
sktthemes CWE-79
6.1
2024-08-29 CVE-2024-43946 Cross-site Scripting vulnerability in Sktthemes SKT Blocks
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Blocks – Gutenberg based Page Builder allows Stored XSS.This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through 1.5.
network
low complexity
sktthemes CWE-79
5.4