plugin

Cms Tree Page View Vulnerabilities

11 known security issues reported for the Cms Tree Page View WordPress plugin. Most recent disclosed May 18, 2023.

3 medium

Running Cms Tree Page View on your site? Check whether your installed version is affected.

Scan your site free

CMS Tree Page View [cms-tree-page-view] < 1.6.8

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.

Affected:
up to 1.6.8
Fixed in:
1.6.8
Disclosed:
May 18, 2023

CVE-2023-30868 on NVD →

CMS Tree Page View <= 1.6.7 - Reflected Cross-Site Scripting via 'post_type'

medium

The CMS Tree Page View plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_type' parameter in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 1.6.8
Fixed in:
1.6.8
Disclosed:
Apr 20, 2023

CVE-2023-30868 on NVD →

CMS Tree Page View [cms-tree-page-view] < 1.6.7

unknown

The CMS Tree Page View plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_type' parameter in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 1.6.7
Fixed in:
1.6.7
Disclosed:
Apr 20, 2023

CMS Tree Page View < 1.4 - Missing Authorization Checks

medium

The CMS Tree Page View plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cms_tpv_move_page function in versions before 1.4. This makes it possible for authenticated attackers with subscriber-level privileges to move pages.

CVSS:
4.3
Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
Oct 20, 2017

CMS Tree Page View [cms-tree-page-view] < 1.4

unknown

The CMS Tree Page View plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cms_tpv_move_page function in versions before 1.4. This makes it possible for authenticated attackers with subscriber-level privileges to move pages.

Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
Oct 20, 2017

CMS Tree Page View [cms-tree-page-view] < 1.2.5

unknown

This plugin is prone to page creation cross site request forgery vulnerability. Update the plugin.

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
May 15, 2015

CMS Tree Page View [cms-tree-page-view] < 1.2.32

unknown

This plugin is prone to multiple parameter cross site scripting vulnerability. Update the plugin.

Affected:
up to 1.2.32
Fixed in:
1.2.32
Disclosed:
May 15, 2015

CMS Tree Page View [cms-tree-page-view] < 0.8.9

unknown

[en] Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.

Affected:
up to 0.8.9
Fixed in:
0.8.9
Disclosed:
Apr 7, 2014

CVE-2012-1834 on NVD →

CMS Tree Page View < 0.8.9 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.

CVSS:
6.1
Affected:
up to 0.8.9
Fixed in:
0.8.9
Disclosed:
Mar 26, 2012

CVE-2012-1834 on NVD →

CMS Tree Page View [cms-tree-page-view] < 1.2.32

unknown

The CMS Tree Page View WordPress plugin was affected by a Multiple Parameter XSS security vulnerability.

Affected:
up to 1.2.32
Fixed in:
1.2.32

CMS Tree Page View [cms-tree-page-view] < 1.2.5

unknown

The CMS Tree Page View WordPress plugin was affected by a Page Creation CSRF security vulnerability.

Affected:
up to 1.2.5
Fixed in:
1.2.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database