majeedraza CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

majeedraza vulnerability overview

Aggregates CVE and security vulnerability intelligence across all majeedraza-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk csrf, with potential vendor impact session compromise across vendor surface production workloads and vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-41848 Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2. [email protected] 5.3 0.15% 2024-12-13 2026-04-28
CVE-2024-6850 The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed [email protected] 4.8 0.19% 2024-09-13 2024-09-27
CVE-2024-45270 WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site. [email protected] 4.3 0.15% 2024-09-02 2025-03-13
CVE-2024-45269 WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site. [email protected] 4.3 0.24% 2024-09-02 2025-03-13
CVE-2024-4372 The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks [email protected] 5.4 0.50% 2024-05-21 2025-04-10
CVE-2024-3703 The Carousel Slider WordPress plugin before 2.2.10 does not validate and escape some of its Slide options before outputting them back in the page/post where the related Slide shortcode is embed, which could allow users with the Editor role and above to perform Stored Cross-Site Scripting attacks [email protected] 4.7 0.27% 2024-05-03 2025-04-10
CVE-2024-1712 The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) [email protected] 4.7 0.11% 2024-04-15 2025-04-08
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence