Skip to main content

Vendor archive

mm-breaking_news_project CVEs

Beta · best-effort

2 CVEs tagged to vendor mm-breaking_news_project0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-8056

Published Sep 12, 2024

The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8054

Published Sep 12, 2024

The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make l…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1