Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nextend Social Login MEDIUM 5.4
CVE-2024-1775

The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting via the ‘error_description’ p…

Fix: 3.1.13+
Fix from $1,600 2024-03-02
Smart Slider 3 HIGH 8.8
CVE-2022-45845

Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9.

Fix: 3.5.1.11+
Fix from $1,950 2024-01-19
Smart Slider 3 MEDIUM 5.4
CVE-2023-0660

The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them bac…

Fix: 3.5.1.14+
Fix from $1,600 2023-03-27
Smart Slider 3 MEDIUM 5.4
CVE-2022-45843

Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.

Fix: 3.5.1.11+
Fix from $1,600 2023-03-23
Smart Slider 3 HIGH 8.8
CVE-2022-3357

The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues whe…

Fix: 3.5.1.11+
Fix from $1,950 2022-10-31
Smart Slider MEDIUM 5.4
CVE-2021-24382

The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to …

Fix: 3.5.0.9+
Fix from $1,600 2021-06-14
Nextend Twitter Connect MEDIUM 6.1
CVE-2015-4557

Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin…

Fix: 1.5.2+
Fix from $1,600 2018-04-12