guzzlehttp/psr7 < 1.9.1 & 2.4.5 - Interpretation Conflict
medium
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild wi...
- CVSS:
- 5.3
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Apr 17, 2023
CVE-2023-29197 on NVD →
WP Offload SES Lite [wp-ses] < 1.4.5
unknown
[en] The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admin dashboard, such as the email's id, subject and recipient, which could lead to Stored Cross-Site Scripting issues when an attacker can control any of these fields, like the subject when filling...
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Jul 6, 2021
CVE-2021-24494 on NVD →
WP Offload SES Lite <= 1.4.4 - Stored Cross-Site Scripting
medium
The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admin dashboard, such as the email's id, subject and recipient, which could lead to Stored Cross-Site Scripting issues when an attacker can control any of these fields, like the subject when filling a con...
- CVSS:
- 5.4
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.5
- Disclosed:
- Jun 29, 2021
CVE-2021-24494 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database