Skip to main content

Vendor/product archive

wpscoop / imageinject CVEs

Beta · best-effort

3 CVEs tagged to wpscoop / imageinject0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-4243

Published Dec 26, 2022

The ImageInject WordPress plugin through 1.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5284

Published Jan 8, 2018

The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1