plugin

Hdw Tube Vulnerabilities

5 known security issues reported for the Hdw Tube WordPress plugin. Most recent disclosed Oct 10, 2016.

2 medium

Running Hdw Tube on your site? Check whether your installed version is affected.

Scan your site free

HDW WordPress Video Gallery <= 1.2 - Reflected Cross-Site Scripting via channel parameter

medium

Reflected XSS in wordpress plugin hdw-tube v1.2 via channel parameter.

CVSS:
6.1
Affected:
up to 1.2
Fix:
No patched version reported
Disclosed:
Oct 10, 2016

CVE-2016-1000135 on NVD →

HDW WordPress Video Gallery <= 1.2 - Reflected Cross-Site Scripting via playlist parameter

medium

Reflected XSS in wordpress plugin hdw-tube v1.2 via playlist parameter.

CVSS:
6.1
Affected:
up to 1.2
Fix:
No patched version reported
Disclosed:
Oct 10, 2016

CVE-2016-1000134 on NVD →

HDW WordPress Video Gallery [hdw-tube] <= 1.2 (closed)

unknown

[en] Reflected XSS in wordpress plugin hdw-tube v1.2

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Oct 10, 2016

CVE-2016-1000134 on NVD →

HDW WordPress Video Gallery [hdw-tube] <= 1.2 (closed)

unknown

[en] Reflected XSS in wordpress plugin hdw-tube v1.2

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Oct 10, 2016

CVE-2016-1000135 on NVD →

HDW WordPress Video Gallery [hdw-tube] < 1.3 (closed)

unknown

Because of this vulnerability, the variable playlist appears to send unsanitized data back to the users browser. Update the plugin.

Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Apr 12, 2016

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database