Lucene search

K

Webp Security Vulnerabilities

cve
cve

CVE-2023-4460

The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS...

5.4CVSS

5.2AI Score

0.0004EPSS

2023-12-04 10:15 PM
12
cve
cve

CVE-2022-36285

Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at...

7.2CVSS

6.9AI Score

0.001EPSS

2022-08-23 04:15 PM
48
3
cve
cve

CVE-2022-34648

Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at...

5.4CVSS

5.2AI Score

0.001EPSS

2022-08-23 04:15 PM
43
4
cve
cve

CVE-2021-25074

The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect...

6.1CVSS

6.1AI Score

0.001EPSS

2022-01-24 08:15 AM
41
cve
cve

CVE-2021-46104

An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the...

7.5CVSS

7.4AI Score

0.002EPSS

2022-01-19 01:15 PM
19
cve
cve

CVE-2019-15834

The webp-converter-for-media plugin before 1.0.3 for WordPress has...

8.8CVSS

8.7AI Score

0.001EPSS

2019-08-30 05:15 PM
311
cve
cve

CVE-2019-15330

The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file...

7.5CVSS

7.6AI Score

0.002EPSS

2019-08-22 07:15 PM
36