Vulnerabilities > Ylefebvre > Link Library > 7.5.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-01-21 | CVE-2024-13404 | Cross-site Scripting vulnerability in Ylefebvre Link Library The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. | 6.1 |
2024-07-20 | CVE-2024-38711 | Unspecified vulnerability in Ylefebvre Link Library Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.7.1. | 6.1 |
2024-06-08 | CVE-2024-35687 | Unspecified vulnerability in Ylefebvre Link Library Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.3. | 6.1 |
2024-05-08 | CVE-2024-4281 | Cross-site Scripting vulnerability in Ylefebvre Link Library The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-19 | CVE-2024-29123 | Unspecified vulnerability in Ylefebvre Link Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6. | 6.1 |
2024-02-20 | CVE-2024-1559 | Cross-site Scripting vulnerability in Ylefebvre Link Library The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. | 6.1 |
2024-02-12 | CVE-2024-24875 | Unspecified vulnerability in Ylefebvre Link Library Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13. | 8.8 |
2024-02-08 | CVE-2024-24879 | Unspecified vulnerability in Ylefebvre Link Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.5.13. | 6.1 |