← Back

Code Snippets

code_snippets

Vendor: Codesnippets • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Codesnippets
1Code Snippets
Jun 17, 2026
May 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter.
1Codesnippets
1Code Snippets
Jun 17, 2026
Jan 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue
1Codesnippets
1Code Snippets
Jun 17, 2026
Jan 28, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.