Activity Log
by Pojo
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-10788 | Hig | 0.40 | 7.2 | 0.01 | Nov 21, 2024 | The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for… | ||
| CVE-2016-10891 | Med | 0.33 | 6.1 | 0.01 | Aug 21, 2019 | The aryo-activity-log plugin before 2.3.3 for WordPress has XSS. | ||
| CVE-2016-10890 | Med | 0.33 | 6.1 | 0.01 | Aug 21, 2019 | The aryo-activity-log plugin before 2.3.2 for WordPress has XSS. | ||
| CVE-2018-8729 | Med | 0.03 | 6.1 | 0.05 | Mar 15, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped. |
- risk 0.40cvss 7.2epss 0.01
The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for…
- risk 0.33cvss 6.1epss 0.01
The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
- risk 0.33cvss 6.1epss 0.01
The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
- risk 0.03cvss 6.1epss 0.05
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped.