Skip to main content

Vendor archive

blog-in-blog_project CVEs

Beta · best-effort

2 CVEs tagged to vendor blog-in-blog_project0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-2436

Published May 31, 2023

The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in versions up to, and including, 2.0.0 due to insufficient inp…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2435

Published May 31, 2023

The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This allows editor-level, and above,…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1