Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High0
Medium4
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2024-11-21

CVE-2024-3815 - Newspaper Plugin

The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Newspaper

CVE-2024-3815

MEDIUM CVSS 5.5 2024-06-15
Threat Entry Updated 2025-05-08

CVE-2022-2627 - Newspaper Theme

The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.

THEME Newspaper

CVE-2022-2627

MEDIUM CVSS 6.1 2022-10-31
Threat Entry Updated 2025-05-07

CVE-2022-2167 - Newspaper Theme

The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting

THEME Newspaper

CVE-2022-2167

MEDIUM CVSS 6.1 2022-10-31
Threat Entry Updated 2024-11-21

CVE-2021-3135 - Newspaper Plugin

An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.

PLUGIN Newspaper

CVE-2021-3135

MEDIUM CVSS 6.1 2021-07-19
Scroll to top