Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Seopress Subscribe
Filtered by product Seopress
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34641 1 Seopress 1 Seopress 2021-08-23 3.5 LOW 5.4 MEDIUM
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.