Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Quantumcloud Subscribe
Filtered by product Slider Hero
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-3074 1 Quantumcloud 1 Slider Hero 2022-09-26 N/A 4.8 MEDIUM
The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.
CVE-2021-24506 1 Quantumcloud 1 Slider Hero 2021-08-26 6.5 MEDIUM 8.8 HIGH
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.