Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Link Library MEDIUM 6.1
CVE-2026-18197

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS).…

Fix: 7.9.4+
Fix from $1,600 2026-07-29
Link Library MEDIUM 5.4
CVE-2025-46237

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allo…

Fix: 7.8.1+
Fix from $1,600 2025-04-22
Bilingual Linker MEDIUM 5.4
CVE-2024-13441

The Bilingual Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bl_otherlang_link_1 parameter in all versions up to, a…

Fix: 2.4.1+
Fix from $1,600 2025-01-25
Link Library MEDIUM 6.1
CVE-2024-13404

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and includi…

Fix: 7.7.3+
Fix from $1,600 2025-01-21
Link Library MEDIUM 6.1
CVE-2024-38711

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Ref…

Fix: 7.7.2+
Fix from $1,600 2024-07-20
Link Library MEDIUM 6.1
CVE-2024-35687

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-libra…

Fix: 7.6.4+
Fix from $1,600 2024-06-08
Link Library MEDIUM 5.4
CVE-2024-4281

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, a…

Fix: 7.7+
Fix from $1,600 2024-05-08
Link Library MEDIUM 6.1
CVE-2024-2325

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all versions up to, and including…

Fix: 7.6.7+
Fix from $1,600 2024-04-09
Link Library MEDIUM 6.1
CVE-2024-29123

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected …

Fix: 7.6.1+
Fix from $1,600 2024-03-19
Link Library MEDIUM 6.1
CVE-2024-1559

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and inclu…

Fix: 7.6.1+
Fix from $1,600 2024-02-20
Link Library HIGH 8.8
CVE-2024-24875

Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.

Fix: after 7.5.13
Fix from $1,950 2024-02-12
Link Library MEDIUM 6.1
CVE-2024-24879

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected …

Fix: after 7.5.13
Fix from $1,600 2024-02-08
Modal Dialog MEDIUM 6.1
CVE-2023-31071

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.14 versions.

Fix: after 3.5.14
Fix from $1,600 2023-08-17
Link Library HIGH 7.5
CVE-2021-25093

The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arb…

Fix: 7.2.8+
Fix from $1,950 2022-02-01
Link Library MEDIUM 6.5
CVE-2021-25092

The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin…

Fix: 7.2.8+
Fix from $1,600 2022-02-01
Link Library MEDIUM 6.1
CVE-2021-25091

The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, le…

Fix: 7.2.9+
Fix from $1,600 2022-02-01