Skip to main content

Vendor/product archive

tagdiv / tagdiv_composer CVEs

Beta · best-effort

8 CVEs tagged to tagdiv / tagdiv_composer0 Critical, 2 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-2806

Published May 8, 2025

The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in all versions up to, and includin…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5212

Published Aug 31, 2024

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insuffi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3886

Published Aug 31, 2024

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insuffi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3814

Published Jun 15, 2024

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 due to insufficien…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3813

Published Jun 15, 2024

The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39166

Published Nov 13, 2023

Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from n/a before 4.4.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3170

Published Sep 11, 2023

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3169

Published Sep 11, 2023

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not vali…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1