olevmedia CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

olevmedia vulnerability overview

Aggregates CVE and security vulnerability intelligence across all olevmedia-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting and vendor risk csrf; exposure may include vendor impact session compromise in vendor surface production workloads and vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-25798 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Olevmedia Olevmedia Shortcodes plugin <= 1.1.9 versions. [email protected] 6.5 0.36% 2023-05-03 2024-11-21
CVE-2023-0168 The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. [email protected] 5.4 0.49% 2023-02-27 2025-03-18
CVE-2015-9421 The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter. [email protected] 6.5 0.87% 2019-09-26 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence