Extension WordPress
Vulnérabilités Slider by 10Web – Responsive Image Slider
Cette page rassemble les failles publiées pour Slider by 10Web – Responsive Image Slider, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Slider by 10Web – Responsive Image Slider
10 fiches
Slider by 10Web <= 1.2.61 – Authenticated (Administrator+) Stored Cross-Site Scripting via Widget
The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget settings in all versions up to, and including, 1.2.61 due to insufficient input sanitization and output escaping. This makes…
*-1.2.61
1.2.62
03/03/2025
Slider by 10Web <= 1.2.61 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.61 due to insufficient input sanitization and output escaping. This makes…
*-1.2.61
1.2.62
03/03/2025
Slider by 10Web <= 1.2.58 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.58 due to insufficient input sanitization and output escaping. This makes…
*-1.2.58
1.2.59
09/09/2024
Slider by 10Web – Responsive Image Slider <= 1.2.57 – Authenticated (Contributor+) SQL Injection via id Parameter
The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.2.57 due to insufficient escaping on the user supplied parameter…
*-1.2.57
1.2.58
07/08/2024
Slider by 10Web <= 1.2.56 – Authenticated (Editor+) Stored Cross-Site Scripting
The Slider by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slider settings in all versions up to, and including, 1.2.56 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-1.2.56
1.2.57
10/07/2024
Slider by 10Web <= 1.2.55 – Authenticated (Editor+) Stored Cross-Site Scripting
The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.55 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.2.55
1.2.56
20/06/2024
Slider by 10Web – Responsive Image Slider <= 1.2.54 – Reflected Cross-Site Scripting
The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.2.54 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.2.54
1.2.55
16/04/2024
Sliderby10Web <= 1.2.52 – Authenticated (Admin+) Cross-Site Scripting
The Sliderby10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slider row links in versions up to, and including, 1.2.52 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to…
*-1.2.52
1.2.53
30/11/2022
Slider by 10Web <= 1.2.51 – Admin+ Stored Cross-Site Scripting
The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
*-1.2.51
1.2.52
26/04/2022
Slider by 10Web <= 1.2.35 – SQL Injection
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn…
*-1.2.35
1.2.36
29/09/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.