Extension WordPress
Vulnérabilités CMS Tree Page View – Reorder Pages with a Drag-and-Drop Tree
Cette page rassemble les failles publiées pour CMS Tree Page View – Reorder Pages with a Drag-and-Drop Tree, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CMS Tree Page View – Reorder Pages with a Drag-and-Drop Tree
3 fiches
CMS Tree Page View <= 1.6.7 – Reflected Cross-Site Scripting via 'post_type'
The CMS Tree Page View plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_type' parameter in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 1.6.8)
1.6.8
20/04/2023
CMS Tree Page View < 1.4 – Missing Authorization Checks
The CMS Tree Page View plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cms_tpv_move_page function in versions before 1.4. This makes it possible for authenticated attackers with subscriber-level privileges to…
[*, 1.4)
1.4
20/10/2017
CMS Tree Page View < 0.8.9 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.
[*, 0.8.9)
0.8.9
26/03/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.