Google Doc Embedder
Source repositories
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10882 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The google-document-embedder plugin before 2.6.2 for WordPress has CSRF. | ||
| CVE-2016-10881 | Med | 0.40 | 6.1 | 0.01 | Aug 14, 2019 | The google-document-embedder plugin before 2.6.2 for WordPress has XSS. | ||
| CVE-2016-10880 | Med | 0.40 | 6.1 | 0.01 | Aug 14, 2019 | The google-document-embedder plugin before 2.6.1 for WordPress has XSS. | ||
| CVE-2012-4915 | 0.07 | — | 0.50 | May 29, 2014 | Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php. | |||
| CVE-2015-1879 | 0.00 | — | 0.02 | Feb 19, 2015 | Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an edit action in the gde-settings page to wp-admin/options-general.php. | |||
| CVE-2014-9173 | 0.00 | — | 0.05 | Dec 2, 2014 | SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter. |
- risk 0.57cvss 8.8epss 0.01
The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.
- risk 0.40cvss 6.1epss 0.01
The google-document-embedder plugin before 2.6.2 for WordPress has XSS.
- risk 0.40cvss 6.1epss 0.01
The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
- CVE-2012-4915May 29, 2014risk 0.07cvss —epss 0.50
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php.
- CVE-2015-1879Feb 19, 2015risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an edit action in the gde-settings page to wp-admin/options-general.php.
- CVE-2014-9173Dec 2, 2014risk 0.00cvss —epss 0.05
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.