Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2024-11-21
CVE-2023-23977 - Social Comments Plugin
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments plugin
PLUGIN
Social Comments
CVE-2023-23977
Risk Score
Threat Entry
Updated 2024-11-21
CVE-2022-0876 - Social Comments Plugin
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed
PLUGIN
Social Comments
CVE-2022-0876
Risk Score
