geminilabs CVE Vulnerabilities & CVE List (9)

Products (CPE): — CVEs: 9

geminilabs vulnerability overview

Aggregates CVE and security vulnerability intelligence across all geminilabs-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting, with potential vendor impact session compromise across vendor surface software deployment and vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 19 of 9 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-1232 The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks [email protected] 8.8 1.78% 2025-03-19 2025-05-09
CVE-2024-3050 The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking [email protected] 9.1 0.56% 2024-05-29 2025-05-21
CVE-2022-46801 Improper Neutralization of Formula Elements in a CSV File vulnerability in Paul Ryley Site Reviews.This issue affects Site Reviews: from n/a through 6.2.0. [email protected] 6.1 0.70% 2023-11-07 2026-04-28
CVE-2023-27629 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. [email protected] 6.5 0.35% 2023-06-22 2024-11-21
CVE-2023-27612 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. [email protected] 6.5 0.34% 2023-06-22 2024-11-21
CVE-2023-1525 The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). [email protected] 4.8 0.50% 2023-05-02 2025-01-30
CVE-2021-24973 The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin [email protected] 6.1 1.31% 2022-01-03 2024-11-21
CVE-2021-24603 The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed [email protected] 5.4 0.60% 2021-09-06 2024-11-21
CVE-2018-0603 Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. [email protected] 6.1 1.31% 2018-06-26 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence