Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High1
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-03-21

CVE-2023-0098 - Simple Urls Plugin

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

PLUGIN Simple Urls

CVE-2023-0098

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2024-11-21

CVE-2023-0099 - Simple Urls Plugin

The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Simple Urls

CVE-2023-0099

MEDIUM CVSS 6.1 2023-02-13
Scroll to top