VYPR

Flexmls IDX Plugin

by Flexmls

CVEs (4)

  • CVE-2025-26900CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX flexmls-idx allows Object Injection.This issue affects Flexmls® IDX: from n/a through <= 3.14.27.

  • CVE-2025-0863MedMar 7, 2025
    risk 0.42cvss 6.4epss 0.00

    The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, 3.14.27 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2024-8719MedOct 17, 2024
    risk 0.40cvss 6.1epss 0.00

    The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like 'MaxBeds' and 'MinBeds' in all versions up to, and including, 3.14.22 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-10552MedJan 25, 2025
    risk 0.35cvss 6.4epss 0.00

    The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘api_key’ and 'api_secret' parameters in all versions up to, and including, 3.14.26 due to insufficient input sanitization and output escaping. This makes it possible for…