All 2 CVE vulnerabilities found in Smash Balloon Social Photo Feed – Easy Social Feeds Plugin, with AI-generated Chinese analysis, references, and POCs.
Vendor: smub
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-15452 | Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query String CWE-79 | 4.7 | Medium | 2026-08-05 |
| CVE-2026-12002 | Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter CWE-352 | 4.7 | Medium | 2026-07-08 |
All 2 known CVE vulnerabilities affecting Smash Balloon Social Photo Feed – Easy Social Feeds Plugin with full Chinese analysis, references, and POCs where available.