Extension WordPress

Vulnérabilités Slider by 10Web – Responsive Image Slider

Cette page rassemble les failles publiées pour Slider by 10Web – Responsive Image Slider, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
0Critiques
10Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Slider by 10Web – Responsive Image Slider

10 fiches

CVE-2024-10565 Moyenne · 4,4
Slider by 10Web – Responsive Image Slider

Slider by 10Web <= 1.2.61 – Authenticated (Administrator+) Stored Cross-Site Scripting via Widget

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget settings in all versions up to, and including, 1.2.61 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.2.61

Correctif

1.2.62

Publication

03/03/2025

CVE-2024-10566 Moyenne · 4,4
Slider by 10Web – Responsive Image Slider

Slider by 10Web <= 1.2.61 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.61 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.2.61

Correctif

1.2.62

Publication

03/03/2025

CVE-2024-8283 Moyenne · 4,4
Slider by 10Web – Responsive Image Slider

Slider by 10Web <= 1.2.58 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.58 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.2.58

Correctif

1.2.59

Publication

09/09/2024

CVE-2024-7150 Élevée · 8,8
Slider by 10Web – Responsive Image Slider

Slider by 10Web – Responsive Image Slider <= 1.2.57 – Authenticated (Contributor+) SQL Injection via id Parameter

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.2.57 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-1.2.57

Correctif

1.2.58

Publication

07/08/2024

CVE-2024-6408 Moyenne · 4,4
Slider by 10Web – Responsive Image Slider

Slider by 10Web <= 1.2.56 – Authenticated (Editor+) Stored Cross-Site Scripting

The Slider by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slider settings in all versions up to, and including, 1.2.56 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-1.2.56

Correctif

1.2.57

Publication

10/07/2024

CVE-2024-6026 Moyenne · 5,5
Slider by 10Web – Responsive Image Slider

Slider by 10Web <= 1.2.55 – Authenticated (Editor+) Stored Cross-Site Scripting

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.55 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.2.55

Correctif

1.2.56

Publication

20/06/2024

CVE-2024-32578 Moyenne · 6,1
Slider by 10Web – Responsive Image Slider

Slider by 10Web – Responsive Image Slider <= 1.2.54 – Reflected Cross-Site Scripting

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.2.54 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.2.54

Correctif

1.2.55

Publication

16/04/2024

CVE-2022-4197 Moyenne · 5,5
Slider by 10Web – Responsive Image Slider

Sliderby10Web <= 1.2.52 – Authenticated (Admin+) Cross-Site Scripting

The Sliderby10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slider row links in versions up to, and including, 1.2.52 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to…

Versions affectées

*-1.2.52

Correctif

1.2.53

Publication

30/11/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités