Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Blog2social MEDIUM 5.4
CVE-2025-4133

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputting them in a dashbo…

Fix: 8.4.0+
Fix from $1,600 2025-05-22
Blog2social MEDIUM 5.4
CVE-2024-7302

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all ve…

Fix: 7.5.5+
Fix from $1,600 2024-08-01
Blog2social CRITICAL 9.9
CVE-2024-3549

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all ve…

Fix: 7.4.2+
Fix from $2,300 2024-06-11
Blog2social MEDIUM 5.3
CVE-2024-3678

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i…

Fix: 7.5.0+
Fix from $1,600 2024-04-26
Blog2social MEDIUM 6.1
CVE-2023-40554

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <= 7.2.0 ve…

Fix: after 7.2.0
Fix from $1,600 2023-09-06
Blog2social MEDIUM 6.1
CVE-2023-3936

The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Fix: 7.2.1+
Fix from $1,600 2023-08-21
Blog2social HIGH 8.8
CVE-2022-3246

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it …

Fix: 6.9.10+
Fix from $1,950 2022-10-25
Blog2social MEDIUM 6.5
CVE-2022-3247

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure…

Fix: 6.9.10+
Fix from $1,600 2022-10-25
Blog2social MEDIUM 6.1
CVE-2021-24956

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before out…

Fix: 6.8.7+
Fix from $1,600 2021-12-21
Blog2social HIGH 8.8
CVE-2021-24137

Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authentic…

Fix: 6.3.1+
Fix from $1,950 2021-03-18
Blog2social MEDIUM 6.1
CVE-2019-17550

The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary …

Fix: 5.9.0+
Fix from $1,600 2019-11-13
Blog2social CRITICAL 9.8
CVE-2019-13572

The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.

Fix: after 5.5.0
Fix from $2,300 2019-08-01
Blog2social MEDIUM 6.1
CVE-2019-9576

The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.

Fix: 5.0.3+
Fix from $1,600 2019-03-05