Skip to main content

Vendor archive

infornweb CVEs

Beta · best-effort

8 CVEs tagged to vendor infornweb0 Critical, 1 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-4567

Published Jun 3, 2025

The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options before outputting the…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23502

Published Jan 31, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in InfornWeb Posts List Designer by Category – List Category Posts Or Recent Pos…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5815

Published Nov 22, 2023

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnera…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-4792

Published Jan 30, 2023

The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4749

Published Jan 30, 2023

The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24913

Published Feb 28, 2022

The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_data AJAX action, allowing attackers to make a logged in hi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24729

Published Nov 23, 2021

The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1