CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPress. |
1Slidervilla 1Testimonial Slider Nov 21, 2024 Sep 26, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS. |
1Slidervilla 1Testimonial Slider Nov 21, 2024 Jan 12, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter). |