VYPR

Tagdiv Composer

by WordPress

CVEs (22)

  • CVE-2026-39712MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in tagDiv tagDiv Composer td-composer allows Code Injection.This issue affects tagDiv Composer: from n/a through <= 5.4.3.

  • CVE-2023-3170MedSep 11, 2023
    risk 0.31cvss 4.8epss 0.00

    The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow users with Admin privileges to perform Stored Cross-Site Scripting attacks even when the…

Page 2 of 2