VYPR

Tabs

by WordPress

CVEs (9)

  • CVE-2025-46522HigApr 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Billy Bryant Tabs gt-tabs allows Stored XSS.This issue affects Tabs: from n/a through <= 4.0.3.

  • CVE-2024-11503MedMar 25, 2025
    risk 0.40cvss 6.1epss 0.00

    The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2022-36375HigJul 25, 2022
    risk 0.40cvss 7.2epss 0.01

    Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.

  • CVE-2024-37120MedJul 22, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Tabs allows Stored XSS.This issue affects Tabs: from n/a through 4.0.6.

  • CVE-2023-40557MedJun 4, 2024
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in PickPlugins Tabs & Accordion allows Code Injection.This issue affects Tabs & Accordion: from n/a through 1.3.10.

  • CVE-2023-0071MedJan 30, 2023
    risk 0.35cvss 5.4epss 0.01

    The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…

  • CVE-2022-1298MedMay 23, 2022
    risk 0.31cvss 4.8epss 0.01

    The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

  • CVE-2022-40215LowSep 23, 2022
    risk 0.22cvss 3.4epss 0.00

    Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress.

  • CVE-2026-65550MedJul 23, 2026
    risk 0.00cvss 5.9epss 0.00

    Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.