Vulnerabilities > Themify > Themify Shortcodes

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2024-43133 Cross-site Scripting vulnerability in Themify Shortcodes
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify Shortcodes allows Stored XSS.This issue affects Themify Shortcodes: from n/a through 2.1.1.
network
low complexity
themify CWE-79
5.4
2024-05-14 CVE-2024-4567 Unspecified vulnerability in Themify Shortcodes
The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themify_button shortcode in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
themify
5.4
2024-03-26 CVE-2024-2732 Unspecified vulnerability in Themify Shortcodes
The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_slider shortcode in all versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
themify
5.4