Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Wp Smiley Project Subscribe
Filtered by product Wp Smiley
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-4139 1 Wp Smiley Project 1 Wp Smiley 2015-06-19 3.5 LOW N/A
Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP Smiley plugin 1.4.1 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the s4w-more parameter to wp-admin/options-general.php.
CVE-2015-4140 1 Wp Smiley Project 1 Wp Smiley 2015-06-19 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in the WP Smiley plugin 1.4.1 for WordPress allows remote attackers to hijack the authentication of editors for requests that conduct cross-site scripting (XSS) attacks via the s4w-more parameter to the smilies4wp.php page to wp-admin/options-general.php.