Vulnerabilities (CVE)

Filtered by vendor Magazine3 Subscribe
Filtered by product Easy Table Of Contents
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-7082 1 Magazine3 1 Easy Table Of Contents 2025-05-28 N/A N/A
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.
CVE-2024-6334 1 Magazine3 1 Easy Table Of Contents 2025-05-21 N/A N/A
The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2024-5573 1 Magazine3 1 Easy Table Of Contents 2025-05-19 N/A N/A
The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed