plugin

Fast Flow Dashboard Vulnerabilities

9 known security issues reported for the Fast Flow Dashboard WordPress plugin. Most recent disclosed Feb 25, 2025.

4 medium

Running Fast Flow Dashboard on your site? Check whether your installed version is affected.

Scan your site free

Fast Flow [fast-flow-dashboard] < 1.2.18

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fastflow Fast Flow allows Reflected XSS. This issue affects Fast Flow: from n/a through 1.2.16.

Affected:
up to 1.2.18
Fixed in:
1.2.18
Disclosed:
Feb 25, 2025

CVE-2025-26868 on NVD →

Fast Flow <= 1.2.16 - Reflected Cross-Site Scripting

medium

The Fast Flow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

CVSS:
6.1
Affected:
up to 1.2.16
Fixed in:
1.2.18
Disclosed:
Feb 22, 2025

CVE-2025-26868 on NVD →

Fast Flow [fast-flow-dashboard] < 1.2.13

unknown

[en] The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.2.13
Fixed in:
1.2.13
Disclosed:
Sep 5, 2022

CVE-2022-2775 on NVD →

Fast Flow <= 1.2.11 - Reflected Cross-Site Scripting

medium

The Fast Flow WordPress plugin is vulnerable to reflected Cross-Site scripting in versions up to, and including, 1.2.11, via the 'p' parameter due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...

CVSS:
6.1
Affected:
up to 1.2.11
Fixed in:
1.2.12
Disclosed:
Aug 15, 2022

Fast Flow [fast-flow-dashboard] < 1.2.12

unknown

The Fast Flow WordPress plugin is vulnerable to reflected Cross-Site scripting in versions up to, and including, 1.2.11, via the 'p' parameter due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...

Affected:
up to 1.2.12
Fixed in:
1.2.12
Disclosed:
Aug 15, 2022

Fast Flow <= 1.2.12 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Fast Flow WordPress plugin is vulnerable to stored Cross-Site scripting in versions up to, and including, 1.2.12, via the multiple parameters due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts...

CVSS:
5.5
Affected:
up to 1.2.12
Fixed in:
1.2.13
Disclosed:
Jul 31, 2022

CVE-2022-2775 on NVD →

Fast Flow [fast-flow-dashboard] < 1.2.11

unknown

[en] The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting

Affected:
up to 1.2.11
Fixed in:
1.2.11
Disclosed:
May 2, 2022

CVE-2022-1269 on NVD →

Fast Flow <= 1.2.10 - Cross-Site Scripting

medium

The Fast Flow WordPress plugin before 1.2.11 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to Reflected Cross-Site Scripting

CVSS:
5.4
Affected:
up to 1.2.10
Fixed in:
1.2.11
Disclosed:
Apr 13, 2022

CVE-2022-1269 on NVD →

Fast Flow [fast-flow-dashboard] < 1.2.12

unknown

The plugin does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 1.2.12
Fixed in:
1.2.12

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database