Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tagdiv Composer MEDIUM 6.1
CVE-2025-2806

The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in al…

Fix: 5.4+
Fix from $1,600 2025-05-08
Composer MEDIUM 5.4
CVE-2025-3510

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 5…

Fix: 5.4.1+
Fix from $1,600 2025-05-02
Tagdiv Composer MEDIUM 6.1
CVE-2024-3886

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and…

Fix: 5.1+
Fix from $1,600 2024-08-31
Tagdiv Composer MEDIUM 6.1
CVE-2024-5212

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and…

Fix: 5.1+
Fix from $1,600 2024-08-31
Tagdiv Composer HIGH 8.8
CVE-2024-3813

The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' sho…

Fix: 4.9+
Fix from $1,950 2024-06-15
Tagdiv Composer MEDIUM 6.1
CVE-2023-39166

Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from …

Fix: 4.4+
Fix from $1,600 2023-11-13
Tagdiv Composer MEDIUM 6.1
CVE-2023-3169

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in …

Fix: 4.2+
Fix from $1,600 2023-09-11
Cloud Library HIGH 8.8
CVE-2023-1597

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and au…

Fix: 2.7+
Fix from $1,950 2023-07-10
Composer MEDIUM 6.1
CVE-2023-1596

The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflecte…

Fix: 4.0+
Fix from $1,600 2023-05-15
Newspaper MEDIUM 6.1
CVE-2022-2167

The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a…

Fix: 12+
Fix from $1,600 2022-10-31
Newspaper MEDIUM 6.1
CVE-2022-2627

The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a…

Fix: 12+
Fix from $1,600 2022-10-31
Newsmag MEDIUM 6.1
CVE-2021-24304

The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Re…

Fix: 5.0+
Fix from $1,600 2021-08-09
Newspaper MEDIUM 6.1
CVE-2021-3135

An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in …

Mitigation only
Fix from $1,600 2021-07-19
Newspaper CRITICAL 9.8
CVE-2016-10972EPSS 9%

The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

Fix: 6.7.2+
Fix from $2,300 2019-09-16
Newspaper CRITICAL 9.8
CVE-2017-18634

The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.

Fix: 6.7.2+
Fix from $2,300 2019-09-16