VYPR

Newspack

by Automattic

Source repositories

CVEs (3)

  • CVE-2024-37423HigNov 1, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Blocks allows Path Traversal.This issue affects Newspack Blocks: from n/a through 3.0.8.

  • CVE-2024-37474MedJul 4, 2024
    risk 0.42cvss 6.5epss 0.00

    Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.

  • CVE-2024-43968MedNov 1, 2024
    risk 0.21cvss 4.3epss 0.00

    Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack: from n/a through 3.8.6.