Lucene search

K

Tonjoostudio Security Vulnerabilities

cve
cve

CVE-2016-10974

The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.

8.8CVSS

8.7AI Score

0.001EPSS

2019-09-17 03:15 PM
18
cve
cve

CVE-2016-10975

The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter.

6.1CVSS

6AI Score

0.001EPSS

2019-09-17 03:15 PM
35
cve
cve

CVE-2018-5311

The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the wp-admin/admin.php?page=tonjoo_excerpt URI.

5.4CVSS

5.2AI Score

0.001EPSS

2018-01-09 05:29 AM
24
cve
cve

CVE-2024-3312

The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.12. This makes it possible for unauthenticated attackers to obtain excerpts of password-protected posts.

5.3CVSS

5.1AI Score

0.0005EPSS

2024-05-02 05:15 PM
44