← Back

Crazy Bone

crazy_bone

Vendor: Crazy Bone Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Crazy Bone Project
1Crazy Bone
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripti...Show more
The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scriptingShow less
1Crazy Bone Project
1Crazy Bone
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header.