VYPR

Favicon By Realfavicongenerator

by RealFaviconGenerator

CVEs (3)

  • CVE-2021-24437MedAug 30, 2021
    risk 0.40cvss 6.1epss 0.01

    The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.

  • CVE-2022-0471MedApr 11, 2022
    risk 0.33cvss 6.1epss 0.01

    The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue

  • CVE-2015-10116MedJun 6, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The manipulation leads to cross-site…