Fast Flow [fast-flow-dashboard] < 1.2.18
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fastflow Fast Flow allows Reflected XSS. This issue affects Fast Flow: from n/a through 1.2.16.
- Affected:
- up to 1.2.18
- Fixed in:
- 1.2.18
- Disclosed:
- Feb 25, 2025
CVE-2025-26868 on NVD →
Fast Flow <= 1.2.16 - Reflected Cross-Site Scripting
medium
The Fast Flow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...
- CVSS:
- 6.1
- Affected:
- up to 1.2.16
- Fixed in:
- 1.2.18
- Disclosed:
- Feb 22, 2025
CVE-2025-26868 on NVD →
Fast Flow [fast-flow-dashboard] < 1.2.13
unknown
[en] The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Sep 5, 2022
CVE-2022-2775 on NVD →
Fast Flow <= 1.2.11 - Reflected Cross-Site Scripting
medium
The Fast Flow WordPress plugin is vulnerable to reflected Cross-Site scripting in versions up to, and including, 1.2.11, via the 'p' parameter due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...
- CVSS:
- 6.1
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.12
- Disclosed:
- Aug 15, 2022
Fast Flow [fast-flow-dashboard] < 1.2.12
unknown
The Fast Flow WordPress plugin is vulnerable to reflected Cross-Site scripting in versions up to, and including, 1.2.11, via the 'p' parameter due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...
- Affected:
- up to 1.2.12
- Fixed in:
- 1.2.12
- Disclosed:
- Aug 15, 2022
Fast Flow <= 1.2.12 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Fast Flow WordPress plugin is vulnerable to stored Cross-Site scripting in versions up to, and including, 1.2.12, via the multiple parameters due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts...
- CVSS:
- 5.5
- Affected:
- up to 1.2.12
- Fixed in:
- 1.2.13
- Disclosed:
- Jul 31, 2022
CVE-2022-2775 on NVD →
Fast Flow [fast-flow-dashboard] < 1.2.11
unknown
[en] The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.11
- Disclosed:
- May 2, 2022
CVE-2022-1269 on NVD →
Fast Flow <= 1.2.10 - Cross-Site Scripting
medium
The Fast Flow WordPress plugin before 1.2.11 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to Reflected Cross-Site Scripting
- CVSS:
- 5.4
- Affected:
- up to 1.2.10
- Fixed in:
- 1.2.11
- Disclosed:
- Apr 13, 2022
CVE-2022-1269 on NVD →
Fast Flow [fast-flow-dashboard] < 1.2.12
unknown
The plugin does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 1.2.12
- Fixed in:
- 1.2.12
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database