Lucene search

K

Tabs Responsive Security Vulnerabilities

cve
cve

CVE-2023-45635

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before...

5.4CVSS

7.1AI Score

0.0004EPSS

2024-06-04 10:15 AM
8
cve
cve

CVE-2024-1846

The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting...

8AI Score

0.0004EPSS

2024-04-15 05:15 AM
61
cve
cve

CVE-2024-27989

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through...

6.5CVSS

7AI Score

0.0004EPSS

2024-04-11 01:25 AM
36
cve
cve

CVE-2024-30497

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through...

8.5CVSS

9.3AI Score

0.0004EPSS

2024-03-29 02:15 PM
30
cve
cve

CVE-2023-52124

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC WP Tabs – Responsive Tabs Plugin for WordPress allows Stored XSS.This issue affects WP Tabs – Responsive Tabs Plugin for WordPress: from n/a through...

6.5CVSS

5.9AI Score

0.0004EPSS

2024-01-05 12:15 PM
48
cve
cve

CVE-2023-24409

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs plugin <= 1.1.15...

7.1CVSS

6AI Score

0.0005EPSS

2023-08-08 12:15 PM
21
cve
cve

CVE-2023-0368

The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above...

5.4CVSS

5.5AI Score

0.001EPSS

2023-06-19 11:15 AM
23
cve
cve

CVE-2023-2184

The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.15 due to insufficient input sanitization and output escaping. This makes it possible for...

6.1CVSS

6AI Score

0.001EPSS

2023-06-09 06:16 AM
18
cve
cve

CVE-2023-25065

Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14...

8.8CVSS

8.8AI Score

0.001EPSS

2023-02-14 12:15 PM
36
cve
cve

CVE-2018-5312

The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to...

5.4CVSS

5.2AI Score

0.001EPSS

2022-10-03 04:22 PM
22
cve
cve

CVE-2022-36375

Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at...

7.2CVSS

6.9AI Score

0.001EPSS

2022-07-25 08:15 PM
39
5
cve
cve

CVE-2022-1298

The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is...

4.8CVSS

4.7AI Score

0.001EPSS

2022-05-23 08:16 AM
42
4
cve
cve

CVE-2022-24108

The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted...

9.8CVSS

9.8AI Score

0.033EPSS

2022-05-17 04:15 PM
45
4
cve
cve

CVE-2021-36893

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <=...

4.8CVSS

4.8AI Score

0.001EPSS

2022-04-11 08:15 PM
58