TFO Graphviz [tfo-graphviz] < 1.10
unknown
[en] A vulnerability was found in chrisy TFO Graphviz Plugin up to 1.9 on WordPress and classified as problematic. Affected by this issue is the function admin_page_load/admin_page of the file tfo-graphviz-admin.php. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to versi...
- Affected:
- up to 1.10
- Fixed in:
- 1.10
- Disclosed:
- Mar 31, 2024
CVE-2015-10131 on NVD →
TFO Graphviz <= 1.9 - Reflected Cross-Site Scripting
medium
The TFO Graphviz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 1.9
- Fixed in:
- 1.10
- Disclosed:
- May 25, 2015
CVE-2015-10131 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database