Extension WordPress
Vulnérabilités Crayon Syntax Highlighter
Cette page rassemble les failles publiées pour Crayon Syntax Highlighter, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Crayon Syntax Highlighter
6 fiches
Crayon Syntax Highlighter <= 2.8.4 – Authenticated (Contributor+) Server Side Request Forgery
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and including, 2.8.4. This can allow authenticated attackers with contributor-level permissions or above to make web…
*-2.8.4
Non indiqué
11/09/2023
Crayon Syntax Highlighter <= 2.8.4 – Cross-Site Request Forgery
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.4. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible…
*-2.8.4
Non indiqué
13/01/2023
Crayon Syntax Highlighter < 2.8.4 – Cross-Site Scripting
The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
[*, 2.8.4)
2.8.4
10/05/2016
Crayon Syntax Highlighter 2.0 – 2.6.10 – Missing Authorization
The Crayon Syntax Highlighter Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the crayon-theme-editor-save AJAX action in versions 2.0 – 2.6.10. This makes it possible for authenticated attackers, with subscriber-level permissions…
2.0-2.6.10
2.7.0
20/04/2015
Crayon Syntax Highlighter <= 2.6.10 – Directory Traversal
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 2.6.10 via the 'data-url' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, potentially…
[*, 2.7.0)
2.7.0
14/04/2015
Crayon Syntax Highlighter Plugin <= 1.13 – Remote File Inclusion
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 1.13 via the crayon_is_php_file function. This allows unauthenticated attackers to include remote files on the server, resulting in code…
*-1.13
1.14
15/10/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.