CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Meteor Slides Project 1Meteor Slides Jun 17, 2026 Jan 7, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escapi...Show more |
1Meteor Slides Project 1Meteor Slides Jun 17, 2026 Dec 2, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Leuze Meteor Slides meteor-slides allows Stored XSS.This issue affects Meteor Slides: from n/a through <= 1.5.7. |
1Meteor Slides Project 1Meteor Slides Jun 17, 2026 Jan 16, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Meteor Slides WordPress plugin before 1.5.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform...Show more |