VYPR
Vendor

10web

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2024-29832MedMar 26, 2024
    risk 0.40cvss 6.1epss 0.00

    The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the current_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be…

  • CVE-2024-29833MedMar 26, 2024
    risk 0.35cvss 5.4epss 0.00

    The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace within the script tag. An…

  • CVE-2024-29810MedMar 26, 2024
    risk 0.35cvss 5.4epss 0.00

    The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted…

  • CVE-2024-29809MedMar 26, 2024
    risk 0.35cvss 5.4epss 0.00

    The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted…

  • CVE-2024-29808MedMar 26, 2024
    risk 0.35cvss 5.4epss 0.00

    The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_id parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted…