Vulnerabilities > Themeum > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-28 | CVE-2023-50859 | Cross-site Scripting vulnerability in Themeum WP Crowdfunding Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through 2.1.6. | 5.4 |
2023-12-15 | CVE-2023-49829 | Unspecified vulnerability in Themeum Tutor LMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a through 2.2.4. | 4.8 |
2023-12-11 | CVE-2023-5757 | Cross-site Scripting vulnerability in Themeum WP Crowdfunding The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | 4.8 |
2023-11-14 | CVE-2023-47532 | Cross-site Scripting vulnerability in Themeum WP Crowdfunding Unauth. | 6.1 |
2023-10-16 | CVE-2023-4805 | Unspecified vulnerability in Themeum Tutor LMS The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | 5.4 |
2023-02-06 | CVE-2023-0236 | Unspecified vulnerability in Themeum Tutor LMS The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | 6.1 |
2022-12-05 | CVE-2022-3830 | Unspecified vulnerability in Themeum WP Page Builder The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | 4.8 |
2022-11-18 | CVE-2022-40963 | Cross-site Scripting vulnerability in Themeum WP Page Builder Multiple Auth. | 5.4 |
2022-10-17 | CVE-2022-2563 | Unspecified vulnerability in Themeum Tutor LMS The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | 4.8 |
2022-01-24 | CVE-2021-25013 | Cross-Site Request Forgery (CSRF) vulnerability in Themeum Qubely The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts | 6.5 |