Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-5528 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share pa… Sassy Social Share 3.3.76+ Fix from $1,6002025-06-07 MEDIUM 5.3 CVE-2024-13230 The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘Sup… Super Socializer 7.14.1+ Fix from $1,6002025-01-21 MEDIUM 6.1 CVE-2024-11252 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share pa… Sassy Social Share 3.3.70+ Fix from $1,6002024-11-30 HIGH 8.1 CVE-2024-9946 The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versi… Super Socializer 7.14+ Fix from $1,9502024-11-06 HIGH 8.1 CVE-2024-10020 The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is … Social Login 1.1.36+ Fix from $1,9502024-11-06 MEDIUM 6.1 CVE-2022-4971EPSS 16% The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_shar… Sassy Social Share after 3.3.3 Fix from $1,6002024-10-16 MEDIUM 6.1 CVE-2024-4924 The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users s… Sassy Social Share 3.6.3+ Fix from $1,6002024-06-12 MEDIUM 6.1 CVE-2024-35706 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows… Social Login 1.1.33+ Fix from $1,6002024-06-08 MEDIUM 5.4 CVE-2024-35707 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows… Social Login 1.1.33+ Fix from $1,6002024-06-08 MEDIUM 5.4 CVE-2024-32674 Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script… Social Login 1.1.32+ Fix from $1,6002024-05-08 MEDIUM 5.4 CVE-2024-29804 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows St… Fancy Comments after 1.2.14 Fix from $1,6002024-03-27 MEDIUM 5.4 CVE-2024-1989 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share… Sassy Social Share 3.3.59+ Fix from $1,6002024-03-06 MEDIUM 6.4 CVE-2024-1448 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all… Sassy Social Share after 3.3.56 Fix from $1,6002024-02-29 MEDIUM 5.4 CVE-2024-24712 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress all… Social Login 1.1.31+ Fix from $1,6002024-02-10 MEDIUM 5.4 CVE-2023-35882 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 versions. Super Socializer after 7.13.52 Fix from $1,6002023-06-20 MEDIUM 5.4 CVE-2023-23977 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disq… Social Comments 1.6.2+ Fix from $1,6002023-04-04 MEDIUM 5.4 CVE-2023-23670 Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions. Fancy Comments 1.2.11+ Fix from $1,6002023-03-30 MEDIUM 5.4 CVE-2022-4484 The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attribut… Super Socializer 7.13.44+ Fix from $1,6002023-01-16 MEDIUM 5.4 CVE-2022-4451 The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the pa… Sassy Social Share 3.3.45+ Fix from $1,6002023-01-16 MEDIUM 6.1 CVE-2021-24987 The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_… Super Socializer 7.13.30+ Fix from $1,6002022-04-11 MEDIUM 6.1 CVE-2021-24746 The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the… Sassy Social Share 3.3.40+ Fix from $1,6002022-03-28 HIGH 8.8 CVE-2021-39321 Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action… Sassy Social Share Patch available Fix from $1,9502021-10-21