Skip to main content

Vendor archive

scriptsbundle CVEs

Beta · best-effort

6 CVEs tagged to vendor scriptsbundle3 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-0169

Published Feb 8, 2025

The DWT - Directory & Listing WordPress Theme is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.4 due to insufficient input sanitiz…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-12857

Published Jan 22, 2025

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's iden…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-12855

Published Jan 8, 2025

The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in all versions u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11350

Published Jan 8, 2025

The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly val…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11349

Published Dec 21, 2024

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's iden…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1