VYPR

Video Carousel Slider With Lightbox

by Nik00726

CVEs (2)

  • CVE-2023-2710MedMay 16, 2023
    risk 0.40cvss 6.1epss 0.01

    The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2019-25212MedSep 11, 2024
    risk 0.32cvss 4.9epss 0.01

    The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…