Extension WordPress
Vulnérabilités Fast Flow
Cette page rassemble les failles publiées pour Fast Flow, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Fast Flow
4 fiches
Fast Flow <= 1.2.16 – Reflected Cross-Site Scripting
The Fast Flow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.2.16
1.2.18
22/02/2025
Fast Flow <= 1.2.11 – Reflected Cross-Site Scripting
The Fast Flow WordPress plugin is vulnerable to reflected Cross-Site scripting in versions up to, and including, 1.2.11, via the 'p' parameter due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-1.2.11
1.2.12
15/08/2022
Fast Flow <= 1.2.12 – Authenticated (Admin+) Stored Cross-Site Scripting
The Fast Flow WordPress plugin is vulnerable to stored Cross-Site scripting in versions up to, and including, 1.2.12, via the multiple parameters due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with…
*-1.2.12
1.2.13
31/07/2022
Fast Flow <= 1.2.10 – Cross-Site Scripting
The Fast Flow WordPress plugin before 1.2.11 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to Reflected Cross-Site Scripting
*-1.2.10
1.2.11
13/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.