Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ultimate Nofollow Project Subscribe
Filtered by product Ultimate Nofollow
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24817 1 Ultimate Nofollow Project 1 Ultimate Nofollow 2021-12-16 3.5 LOW 5.4 MEDIUM
The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks