Vulnerabilities > Ylefebvre

DATE CVE VULNERABILITY TITLE RISK
2025-01-25 CVE-2024-13441 Cross-site Scripting vulnerability in Ylefebvre Bilingual Linker
The Bilingual Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bl_otherlang_link_1 parameter in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping.
network
low complexity
ylefebvre CWE-79
5.4
2025-01-21 CVE-2024-13404 Cross-site Scripting vulnerability in Ylefebvre Link Library
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping.
network
low complexity
ylefebvre CWE-79
6.1
2024-07-20 CVE-2024-38711 Unspecified vulnerability in Ylefebvre Link Library
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.7.1.
network
low complexity
ylefebvre
6.1
2024-06-08 CVE-2024-35687 Unspecified vulnerability in Ylefebvre Link Library
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.3.
network
low complexity
ylefebvre
6.1
2024-05-08 CVE-2024-4281 Cross-site Scripting vulnerability in Ylefebvre Link Library
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
ylefebvre CWE-79
5.4
2024-03-19 CVE-2024-29123 Unspecified vulnerability in Ylefebvre Link Library
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.
network
low complexity
ylefebvre
6.1
2024-02-20 CVE-2024-1559 Cross-site Scripting vulnerability in Ylefebvre Link Library
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping.
network
low complexity
ylefebvre CWE-79
6.1
2024-02-12 CVE-2024-24875 Unspecified vulnerability in Ylefebvre Link Library
Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.
network
low complexity
ylefebvre
8.8
2024-02-08 CVE-2024-24879 Unspecified vulnerability in Ylefebvre Link Library
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.5.13.
network
low complexity
ylefebvre
6.1
2023-08-17 CVE-2023-31071 Unspecified vulnerability in Ylefebvre Modal Dialog
Unauth.
network
low complexity
ylefebvre
6.1