| CVE-2026-3885 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_box Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2026-04-16 02:25:17 | Deep Dive |
| CVE-2026-0737 | Shortcodes Ultimate <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'su_lightbox' Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2026-04-04 07:41:59 | Deep Dive |
| CVE-2026-0738 | Shortcodes Ultimate <= 7.4.8 - authenticated (Contributor+) Stored Cross-Site Scripting via 'su_carousel' Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2026-04-04 07:41:58 | Deep Dive |
| CVE-2026-2480 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'max_width' Shortcode Attribute | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2026-03-31 22:26:04 | Deep Dive |
| CVE-2025-12800 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.5 - Authenticated (Administrator+) Server-Side Request Forgery | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2025-11-23 22:26:40 | Deep Dive |
| CVE-2025-8015 | Shortcodes Ultimate <= 7.4.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title and Slide Link | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2025-07-22 14:43:08 | Deep Dive |
| CVE-2025-7369 | Shortcodes Ultimate <= 7.4.2 - Cross-Site Request Forgery to Arbitrary Shortcode Execution | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.1 | 2025-07-21 07:23:25 | Deep Dive |
| CVE-2025-7354 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2025-07-21 07:23:25 | Deep Dive |
| CVE-2025-5567 | Shortcodes Ultimate <= 7.4.0 - Authenticted (Contributor+) Stored Cross-Site Scripting via 'data-url' Attribute | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2025-07-04 02:22:33 | Deep Dive |
| CVE-2024-5647 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library | blossomthemes | BlossomThemes Social Feed | Medium | 6.4 | 2025-07-03 09:22:19 | Deep Dive |
| CVE-2025-0370 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via src Parameter | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2025-03-04 09:22:37 | Deep Dive |
| CVE-2024-8500 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 5.4 | 2024-10-23 11:04:27 | Deep Dive |
| CVE-2024-4821 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_lightbox Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2024-06-05 08:33:17 | Deep Dive |
| CVE-2024-4553 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_members Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2024-05-21 09:31:51 | Deep Dive |
| CVE-2024-3548 | Shortcodes Ultimate < 7.1.2 - Contributor+ Stored XSS | Unknown | WP Shortcodes Plugin — Shortcodes Ultimate | - | - | 2024-05-15 06:00:03 | Deep Dive |
| CVE-2024-3550 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2024-05-02 16:52:33 | Deep Dive |
| CVE-2024-3188 | Shortcodes Ultimate < 7.1.0 - Contributor+ Stored XSS | Unknown | WP Shortcodes Plugin — Shortcodes Ultimate | - | - | 2024-04-26 05:00:05 | Deep Dive |
| CVE-2024-2583 | Shortcodes Ultimate < 7.0.5 - Contributor+ Stored XSS | Unknown | WP Shortcodes Plugin — Shortcodes Ultimate | 中危 | - | 2024-04-13 05:00:02 | Deep Dive |
| CVE-2024-1808 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_qrcode Shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2024-02-28 12:50:50 | Deep Dive |
| CVE-2024-0792 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode | gn_themes | WP Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.4 | 2024-02-20 18:56:19 | Deep Dive |