Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-2806 The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in al… Tagdiv Composer 5.4+ Fix from $1,6002025-05-08 MEDIUM 5.4 CVE-2025-3510 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 5… Composer 5.4.1+ Fix from $1,6002025-05-02 MEDIUM 6.1 CVE-2024-3886 The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and… Tagdiv Composer 5.1+ Fix from $1,6002024-08-31 MEDIUM 6.1 CVE-2024-5212 The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and… Tagdiv Composer 5.1+ Fix from $1,6002024-08-31 HIGH 8.8 CVE-2024-3813 The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' sho… Tagdiv Composer 4.9+ Fix from $1,9502024-06-15 MEDIUM 6.1 CVE-2023-39166 Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from … Tagdiv Composer 4.4+ Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2023-3169 The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in … Tagdiv Composer 4.2+ Fix from $1,6002023-09-11 HIGH 8.8 CVE-2023-1597 The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and au… Cloud Library 2.7+ Fix from $1,9502023-07-10 MEDIUM 6.1 CVE-2023-1596 The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflecte… Composer 4.0+ Fix from $1,6002023-05-15 MEDIUM 6.1 CVE-2022-2167 The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a… Newspaper 12+ Fix from $1,6002022-10-31 MEDIUM 6.1 CVE-2022-2627 The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a… Newspaper 12+ Fix from $1,6002022-10-31 MEDIUM 6.1 CVE-2021-24304 The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Re… Newsmag 5.0+ Fix from $1,6002021-08-09 MEDIUM 6.1 CVE-2021-3135 An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in … Newspaper Mitigation only Fix from $1,6002021-07-19 CRITICAL 9.8 CVE-2016-10972EPSS 9% The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. Newspaper 6.7.2+ Fix from $2,3002019-09-16 CRITICAL 9.8 CVE-2017-18634 The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. Newspaper 6.7.2+ Fix from $2,3002019-09-16