sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical0
High0
Medium1
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-06-17

Fathom Analytics - Cross-Site Scripting (XSS) (CVE-2021-41836)

The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the $site_id parameter found in the ~/fathom-analytics.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 3.0.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Fathom Analytics

CVE-2021-41836

MEDIUM CVSS 4.8 2021-12-14