Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-45460 1 Info-d-74 1 Flipping Cards 2026-04-01 4.8 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manu225 Flipping Cards flipping-cards allows Stored XSS.This issue affects Flipping Cards: from n/a through <= 1.30.
CVE-2024-3937 1 Info-d-74 1 Playlist For Youtube 2025-05-21 4.8 Medium
The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-4602 1 Info-d-74 1 Embed Peertube Playlist 2025-05-15 5.4 Medium
The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2023-45645 1 Info-d-74 1 Open Street Map 2024-11-21 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in InfoD74 WP Open Street Map plugin <= 1.25 versions.