Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-2806
The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in al…
Tagdiv Composer
5.4+
MEDIUM 5.4
CVE-2025-3510
The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 5…
Composer
5.4.1+
MEDIUM 6.1
CVE-2024-3886
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and…
Tagdiv Composer
5.1+
MEDIUM 6.1
CVE-2024-5212
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and…
Tagdiv Composer
5.1+
HIGH 8.8
CVE-2024-3813
The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' sho…
Tagdiv Composer
4.9+
MEDIUM 6.1
CVE-2023-39166
Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from …
Tagdiv Composer
4.4+
MEDIUM 6.1
CVE-2023-3169
The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in …
Tagdiv Composer
4.2+
HIGH 8.8
CVE-2023-1597
The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and au…
Cloud Library
2.7+
MEDIUM 6.1
CVE-2023-1596
The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflecte…
Composer
4.0+
MEDIUM 6.1
CVE-2022-2167
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a…
Newspaper
12+
MEDIUM 6.1
CVE-2022-2627
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a…
Newspaper
12+
MEDIUM 6.1
CVE-2021-24304
The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Re…
Newsmag
5.0+
MEDIUM 6.1
CVE-2021-3135
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in …
Newspaper
Mitigation only
CRITICAL 9.8
CVE-2016-10972EPSS 9%
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
Newspaper
6.7.2+
CRITICAL 9.8
CVE-2017-18634
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
Newspaper
6.7.2+