Slideshow SE [slideshow-se] <= 2.5.20 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in John West Slideshow SE allows Stored XSS.This issue affects Slideshow SE: from n/a through 2.5.17.
- Affected:
- up to 2.5.20
- Fix:
- No patched version reported
- Disclosed:
- Jun 21, 2024
CVE-2024-35769 on NVD →
Slideshow SE [slideshow-se] < 2.5.18
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John West Slideshow SE PHP Local File Inclusion.This issue affects Slideshow SE: from n/a through 2.5.17.
- Affected:
- up to 2.5.18
- Fixed in:
- 2.5.18
- Disclosed:
- Jun 21, 2024
CVE-2024-35778 on NVD →
Slideshow SE <= 2.5.17 - Authenticated (Author+) Limited Local File Inclusion
high
The Slideshow SE plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.17. This makes it possible for authenticated attackers, with author-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. T...
- CVSS:
- 8.8
- Affected:
- up to 2.5.17
- Fixed in:
- 2.5.18
- Disclosed:
- Jun 19, 2024
CVE-2024-35778 on NVD →
Slideshow SE <= 2.5.20 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Slideshow SE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 2.5.20
- Fixed in:
- 2.6.0
- Disclosed:
- Jun 18, 2024
CVE-2024-35769 on NVD →
Slideshow SE [slideshow-se] < 2.5.6
unknown
[en] Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Mar 17, 2023
CVE-2022-43461 on NVD →
Slideshow SE [slideshow-se] < 2.5.6
unknown
[en] Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Mar 16, 2023
CVE-2022-41554 on NVD →
Slideshow SE <= 2.5.5 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Slideshow SE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Oct 28, 2022
CVE-2022-41554 on NVD →
Slideshow SE <= 2.5.5 - Authenticated (Subscriber+) Cross-Site Scripting
medium
The Slideshow SE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in certain plugin configurations in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inje...
- CVSS:
- 6.4
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Oct 28, 2022
CVE-2022-43461 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database