VYPR

Yml For Yandex Market

by Icopydoc

CVEs (3)

  • CVE-2023-30473HigAug 16, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov YML for Yandex Market plugin <= 3.10.7 versions.

  • CVE-2024-9378MedOct 2, 2024
    risk 0.40cvss 6.1epss 0.00

    The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 4.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2024-1365MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the feed_id parameter in all versions up to, and including, 4.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…