| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-3936 | Blog2Social < 7.2.1 - Reflected XSS | Unknown | Blog2Social: Social Media Auto Post & Scheduler | 中危 | - | 2023-08-21 12:29:50 | Deep Dive |
| CVE-2023-40172 | Cross-Site Request Forgery (CSRF) in fobybus/social-media-skeleton | fobybus | social-media-skeleton | Medium | 6.5 | 2023-08-18 21:48:42 | Deep Dive |
| CVE-2023-40173 | Unsalted passwords in fobybus/social-media-skeleton | fobybus | social-media-skeleton | High | 7.5 | 2023-08-18 21:47:18 | Deep Dive |
| CVE-2023-40174 | Insufficient Session Expiration in fobybus/social-media-skeleton | fobybus | social-media-skeleton | Medium | 6.8 | 2023-08-18 21:41:54 | Deep Dive |
| CVE-2023-39518 | social-media-skeleton stored Cross-site Scripting vulnerability | fobybus | social-media-skeleton | Medium | 5.4 | 2023-08-08 18:31:36 | Deep Dive |
| CVE-2023-39344 | social-media-skeleton vulnerable to Pre-Auth SQLi leading to RCE | fobybus | social-media-skeleton | Critical | 10.0 | 2023-08-04 19:49:20 | Deep Dive |
| CVE-2023-0958 | Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function | inisev | Redirection | Medium | 4.3 | 2023-07-28 04:37:04 | Deep Dive |
| CVE-2023-3977 | Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function | inisev | Redirection | Medium | 4.3 | 2023-07-28 04:37:03 | Deep Dive |
| CVE-2023-25036 | WordPress Social Media Icons Widget Plugin <= 1.6 is vulnerable to Cross Site Request Forgery (CSRF) | akhlesh-nagar, a.ankit | Social Media Icons Widget | Medium | 4.3 | 2023-07-18 12:17:40 | Deep Dive |
| CVE-2023-0172 | Juicer < 1.11 - Contributor+ Stored XSS | Unknown | Embed, curate & aggregate social media feeds into your website using JUICER | 中危 | - | 2023-03-13 16:03:33 | Deep Dive |
| CVE-2022-4544 | MashShare < 3.8.7 - Contributor+ Stored XSS | Unknown | Social Media Share Buttons | MashShare | 中危 | - | 2023-01-16 15:38:05 | Deep Dive |
| CVE-2022-3247 | Blog2Social < 6.9.10 - Subscriber+ SSRF | Unknown | Blog2Social: Social Media Auto Post & Scheduler | 中危 | - | 2022-10-25 00:00:00 | Deep Dive |
| CVE-2022-3246 | Blog2Social < 6.9.10 - Subscriber+ SQLi | Unknown | Blog2Social: Social Media Auto Post & Scheduler | 高危 | - | 2022-10-25 00:00:00 | Deep Dive |
| CVE-2022-2763 | WP Socializer < 7.3 - Admin+ Stored Cross-Site Scripting | Unknown | WP Socializer – Simple & Easy Social Media Share Icons | 中危 | - | 2022-10-03 13:45:23 | Deep Dive |
| CVE-2021-36839 | WordPress Social Media Follow Buttons Bar plugin <= 4.73 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Space X-Chimp | Social Media Follow Buttons Bar (WordPress plugin) | Medium | 4.8 | 2022-09-30 16:14:55 | Deep Dive |
| CVE-2021-36849 | WordPress Social Media Share Buttons plugin <= 3.8.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | René Hermenau | Social Media Share Buttons | MashShare (WordPress plugin) | Low | 3.4 | 2022-07-20 18:35:30 | Deep Dive |
| CVE-2021-36848 | WordPress Social Media Feather plugin <= 2.0.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Socialmediafeather | Social Media Feather (WordPress plugin) | Low | 3.4 | 2022-04-11 19:36:56 | Deep Dive |
| CVE-2021-24956 | Blog2Social < 6.8.7 - Reflected Cross-Site Scripting | Unknown | Blog2Social: Social Media Auto Post & Scheduler | 中危 | - | 2021-12-21 08:45:39 | Deep Dive |
| CVE-2021-36843 | WordPress Floating Social Media Icon plugin <= 4.3.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Acurax Technologies | Floating Social Media Icon (WordPress plugin) | Medium | 4.8 | 2021-11-26 16:35:15 | Deep Dive |
| CVE-2021-24656 | Simple Social Media Share Buttons < 3.2.4 - Authenticated Stored Cross-Site Scripting | Unknown | Simple Social Media Share Buttons – Social Sharing for Everyone | 中危 | - | 2021-10-11 10:45:36 | Deep Dive |