Weavertheme
weavertheme
6 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Weavertheme 1Weaver Xtreme Theme Support Jun 17, 2026 Jun 5, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and including, 6.4 due to insufficient input sanitization and output...Show more |
1Weavertheme 1Weaver Xtreme Theme Support Jun 17, 2026 Jan 11, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions up to, and including, 6.3.0 due to insufficient input sanitization and output escaping on user suppl...Show more |
1Weavertheme 1Weaver Xtreme Theme Support Jun 17, 2026 Oct 16, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suita...Show more |
The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 1.6. This makes it possible for authentic...Show more |
The Weaver Xtreme Theme for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 5.0.7. This makes it possible for authenticate...Show more |
1Weavertheme 1Weaver Xtreme Theme Support Jun 17, 2026 Apr 24, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users...Show more |