Thème WordPress
Vulnérabilités Listeo – Directory & Listings With Booking – WordPress Theme
Cette page rassemble les failles publiées pour Listeo – Directory & Listings With Booking – WordPress Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Listeo – Directory & Listings With Booking – WordPress Theme
3 fiches
Listeo <= 2.0.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via soundcloud Shortcode
The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in version less than, or equal to, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.0.8
2.0.9
24/10/2025
Listeo – Directory & Listings With Booking – WordPress Theme < 1.6.11 – Insecure Direct Object Reference
The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.
[*, 1.6.11)
1.6.11
16/05/2021
Listeo – Directory & Listings With Booking – WordPress Theme < 1.6.11 – Cross-Site Scripting
The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues
[*, 1.6.11)
1.6.11
10/02/2021
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.