Prettylinks
by Caseproof
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-9457 | Hig | 0.47 | 7.2 | 0.02 | Oct 10, 2019 | The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter. | ||
| CVE-2011-4595 | Med | 0.43 | 6.1 | 0.02 | Jan 10, 2020 | Pretty-Link WordPress plugin 1.5.2 has XSS | ||
| CVE-2024-2326 | Med | 0.28 | 4.3 | 0.00 | Mar 23, 2024 | The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation when saving plugin settings.… | ||
| CVE-2013-1636 | 0.00 | — | 0.06 | Mar 12, 2014 | Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3,… |
- risk 0.47cvss 7.2epss 0.02
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
- risk 0.43cvss 6.1epss 0.02
Pretty-Link WordPress plugin 1.5.2 has XSS
- risk 0.28cvss 4.3epss 0.00
The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation when saving plugin settings.…
- CVE-2013-1636Mar 12, 2014risk 0.00cvss —epss 0.06
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3,…