VYPR
Vendor

RealFaviconGenerator

Products
2
CVEs
3
Across products
4
Status
Private

Products

2

Recent CVEs

3
  • CVE-2021-24437MedAug 30, 2021
    risk 0.40cvss 6.1epss 0.01

    The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.

  • CVE-2022-0471MedApr 11, 2022
    risk 0.33cvss 6.1epss 0.01

    The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue

  • CVE-2015-10116MedJun 6, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The manipulation leads to cross-site…