Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2025-03-21
CVE-2023-0098 - Simple Urls Plugin
The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.
PLUGIN
Simple Urls
CVE-2023-0098
Risk Score
Threat Entry
Updated 2024-11-21
CVE-2023-0099 - Simple Urls Plugin
The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
PLUGIN
Simple Urls
CVE-2023-0099
Risk Score
