CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilt...Show more |
1Simple Banner Project 1Simple Banner Jun 17, 2026 Sep 6, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code` parameter in versions up to, and including, 2.11.0 due to insufficient input sanitization and outp...Show more |
1Simple Banner Project 1Simple Banner Jun 17, 2026 Aug 22, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability...Show more |
1Simple Banner Project 1Simple Banner Jun 17, 2026 Aug 23, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability...Show more |