CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Custom Field Suite Project 1Custom Field Suite Jun 17, 2026 Jun 20, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used...Show more |
1Custom Field Suite Project 1Custom Field Suite Jun 17, 2026 Jun 20, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 due to insufficient escaping on the user supplied parameter and lack...Show more |
1Custom Field Suite Project 1Custom Field Suite Jun 17, 2026 Jun 20, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output esca...Show more |
1Custom Field Suite Project 1Custom Field Suite Jun 17, 2026 Jun 12, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output es...Show more |
1Custom Field Suite Project 1Custom Field Suite Jun 17, 2026 May 14, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and out...Show more |
1Custom Field Suite Project 1Custom Field Suite Jun 17, 2026 Feb 29, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the met...Show more |
1Custom Field Suite Project 1Custom Field Suite Jun 17, 2026 May 18, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions. |
1Custom Field Suite Project 1Custom Field Suite Jun 17, 2026 May 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins. |