Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Custom Twitter Feeds HIGH 8.8
CVE-2024-49685

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Fo…

Fix: 2.2.4+
Fix from $1,950 2024-10-31
Feeds For Youtube MEDIUM 5.4
CVE-2024-6256

The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's…

Fix: 2.2.2+
Fix from $1,600 2024-07-11
Custom Twitter Feeds HIGH 8.8
CVE-2023-52136

Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Tw…

Fix: after 2.1.2
Fix from $1,950 2024-01-05
Feeds For Youtube MEDIUM 5.4
CVE-2023-4841

The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in versions up to, and including…

Fix: after 2.1
Fix from $1,600 2023-09-14
Custom Twitter Feeds HIGH 8.8
CVE-2022-33974

Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.

Fix: after 1.8.4
Fix from $1,950 2023-05-29
Smash Balloon Social Post Feed MEDIUM 5.4
CVE-2022-4477

The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting the…

Fix: 4.1.6+
Fix from $1,600 2023-01-16
Smash Balloon Social Post Feed MEDIUM 5.4
CVE-2021-25065

The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.

Fix: 4.1.1+
Fix from $1,600 2022-01-17
Smash Balloon Social Post Feed MEDIUM 5.4
CVE-2021-24918

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. A…

Fix: 4.0.1+
Fix from $1,600 2021-11-29
Smash Balloon Social Post Feed MEDIUM 6.1
CVE-2021-24508

The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX acti…

Fix: 2.19.2+
Fix from $1,600 2021-09-13