Lucene search

K

Colorlib Security Vulnerabilities

cve
cve

CVE-2020-36721

The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' fi...

6.5CVSS

6.5AI Score

0.001EPSS

2023-06-07 02:15 AM
19
cve
cve

CVE-2020-36708

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite ...

9.8CVSS

9.7AI Score

0.024EPSS

2023-06-07 02:15 AM
19
cve
cve

CVE-2022-45358

Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4...

5.4CVSS

5.3AI Score

0.0005EPSS

2023-04-13 12:15 PM
20
cve
cve

CVE-2022-45849

Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4...

5.4CVSS

5.3AI Score

0.001EPSS

2023-04-16 09:15 AM
37
2
cve
cve

CVE-2022-1945

The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite...

4.8CVSS

4.7AI Score

0.001EPSS

2022-06-20 11:15 AM
51
3
cve
cve

CVE-2015-1494

The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and.....

5.9AI Score

0.005EPSS

2015-02-17 03:59 PM
26
2