Extension WordPress
Vulnérabilités Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
Cette page rassemble les failles publiées pour Smash Balloon Social Photo Feed – Easy Social Feeds Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
6 fiches
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 – Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on…
*-6.11.1
6.11.2
08/07/2026
Smash Balloon Instagram Feed <= 6.9.0 (Free) & <= 6.8.0 (Pro) – Authenticated (Contributor+) Stored Cross-Site Scripting via `data-plugin` Attribute
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-plugin` attribute in all versions up to, and including, 6.9.0 (Free) and 6.8.0 (Pro) due to…
*-6.9.0
6.9.1
28/05/2025
Smash Balloon Plugins (Various Versions) – Reflected Cross-Site Scripting
Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to…
*-2.9.1
2.9.2
20/07/2021
Smash Balloon Social Photo Feed <= 1.11.3 – Cross-Site Request Forgery to Back-Up Deletion
The Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.3. This is due to missing or incorrect nonce validation on the sbi_clear_backups() function. This makes it…
[*, 1.12)
1.12
05/03/2019
Smash Balloon Social Photo Feed <= 1.5.1 – Reflected Cross-Site Scripting
The Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘access_token’ parameter in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.5.1
1.6
18/01/2018
Smash Balloon Social Photo Feed <= 1.4.6.2 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in the settings page in versions up to, and including, 1.4.6.2 due to insufficient input sanitization and output escaping…
*-1.4.6.2
1.4.7
19/11/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.