Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High1
Medium2
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-12-12

CVE-2025-4970 - Bsk Pdf Manager Plugin

The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Bsk Pdf Manager

CVE-2025-4970

MEDIUM CVSS 5.5 2025-12-12
Threat Entry Updated 2024-11-21

CVE-2023-5110 - Bsk Pdf Manager Plugin

The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bsk-pdfm-category-dropdown' shortcode in versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bsk Pdf Manager

CVE-2023-5110

MEDIUM CVSS 6.4 2023-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24860 - Bsk Pdf Manager Plugin

The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue

PLUGIN Bsk Pdf Manager

CVE-2021-24860

HIGH CVSS 7.2 2021-11-29
Scroll to top