Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Testimonial Rotator Project Subscribe
Filtered by product Testimonial Rotator
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24156 1 Testimonial Rotator Project 1 Testimonial Rotator 2021-04-08 3.5 LOW 5.4 MEDIUM
Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation
CVE-2020-26672 1 Testimonial Rotator Project 1 Testimonial Rotator 2020-11-19 3.5 LOW 5.4 MEDIUM
Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.