Known vulnerabilities in the More plugin
45 security advisories have been published for the More plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- More - Cross-Site Scripting (XSS) (CVE-2026-18331) HIGH
- More - Path Traversal (CVE-2026-15056) MEDIUM
- More - SQL Injection (CVE-2026-11920) MEDIUM
- More - Cross-Site Scripting (XSS) (CVE-2026-16583) MEDIUM
- More - Remote Code Execution (CVE-2026-14282) CRITICAL
- More - Cross-Site Scripting (XSS) (CVE-2026-15782) MEDIUM
- More - SQL Injection (CVE-2026-13010) MEDIUM
- More - Broken Access Control (CVE-2026-12134) MEDIUM
- More - Security Vulnerability (CVE-2026-12127) MEDIUM
- More - Broken Access Control (CVE-2026-12133) MEDIUM
- More - Cross-Site Scripting (XSS) (CVE-2026-11358) MEDIUM
- More - Cross-Site Scripting (XSS) (CVE-2026-7796) MEDIUM
- More - Security Vulnerability (CVE-2026-7792) MEDIUM
- More - Broken Access Control (CVE-2026-10038) MEDIUM
- More - SQL Injection (CVE-2026-6929) HIGH
- More - SQL Injection (CVE-2026-7619) MEDIUM
- More - Security Vulnerability (CVE-2026-3177) MEDIUM
- More - Cross-Site Scripting (XSS) (CVE-2025-12045) MEDIUM
- More - SQL Injection (CVE-2025-11893) HIGH
- More - Server-Side Request Forgery (SSRF) (CVE-2025-10874) MEDIUM
- More - Path Traversal (CVE-2025-7721) CRITICAL
- More - Remote Code Execution (CVE-2025-9216) HIGH
- More - Path Traversal (CVE-2025-9215) MEDIUM
- More - Cross-Site Scripting (XSS) (CVE-2025-5275) MEDIUM
- More - Cross-Site Scripting (XSS) (CVE-2025-3794) MEDIUM
- More - SQL Injection (CVE-2025-1323) HIGH
- More - Cross-Site Scripting (XSS) (CVE-2025-1324) MEDIUM
- More - Broken Access Control (CVE-2025-1325) MEDIUM
- More - Information Disclosure (CVE-2025-1322) MEDIUM
- More - Information Disclosure (CVE-2024-11153) MEDIUM