Newstatpress Project
newstatpress_project
10 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Newstatpress Project 1Newstatpress Nov 21, 2024 Jun 24, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The attack...Show more |
1Newstatpress Project 1Newstatpress Jun 17, 2026 Feb 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues. |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The newstatpress plugin before 1.0.1 for WordPress has SQL injection. |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header. |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element. |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element. |
1Newstatpress Project 1Newstatpress Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The newstatpress plugin before 1.0.6 for WordPress has reflected XSS. |
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter...Show more |
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search...Show more |