Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Asset Cleanup\ Subscribe
Filtered by product Page Speed Booster Project
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-36899 1 Asset Cleanup\ 1 Page Speed Booster Project 2022-10-11 N/A 4.8 MEDIUM
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Booster plugin <= 1.3.8.4 at WordPress.
CVE-2021-24937 1 Asset Cleanup\ 1 Page Speed Booster Project 2022-02-04 4.3 MEDIUM 6.1 MEDIUM
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue
CVE-2021-24983 1 Asset Cleanup\ 1 Page Speed Booster Project 2022-02-04 4.3 MEDIUM 6.1 MEDIUM
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue