Clogica
Products
4- 4 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24324 | Med | 0.42 | 6.5 | 0.01 | May 17, 2021 | The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site… | ||
| CVE-2021-24328 | Med | 0.40 | 6.2 | 0.01 | Jun 1, 2021 | The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS… | ||
| CVE-2021-24325 | Med | 0.40 | 6.1 | 0.01 | May 17, 2021 | The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute. | ||
| CVE-2016-10896 | Med | 0.40 | 6.1 | 0.01 | Aug 21, 2019 | The seo-redirection plugin before 4.3 for WordPress has stored XSS. | ||
| CVE-2022-40695 | Med | 0.35 | 5.4 | 0.00 | Nov 18, 2022 | Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress. | ||
| CVE-2022-38704 | Med | 0.35 | 5.4 | 0.00 | Sep 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history. | ||
| CVE-2021-24326 | Med | 0.35 | 5.4 | 0.01 | May 17, 2021 | The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute. | ||
| CVE-2021-24187 | Med | 0.35 | 5.4 | 0.01 | Apr 5, 2021 | The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute. | ||
| CVE-2021-24327 | Med | 0.31 | 4.8 | 0.01 | May 17, 2021 | The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads |
- risk 0.42cvss 6.5epss 0.01
The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site…
- risk 0.40cvss 6.2epss 0.01
The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS…
- risk 0.40cvss 6.1epss 0.01
The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.
- risk 0.40cvss 6.1epss 0.01
The seo-redirection plugin before 4.3 for WordPress has stored XSS.
- risk 0.35cvss 5.4epss 0.00
Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history.
- risk 0.35cvss 5.4epss 0.01
The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.
- risk 0.35cvss 5.4epss 0.01
The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.
- risk 0.31cvss 4.8epss 0.01
The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads