Export limit exceeded: 401189 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 401189 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 10638 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 401189 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93896 2 Wordpress-extensions, Wpfront 2 Wpfront Notification Bar, Notification Bar 2026-10-04 6.1 Medium
The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the debug-log output path (write_debug_logs) reflecting the raw value of $_SERVER['REQUEST_URI'] through vprintf() directly inside a <script> block emitted on wp_footer, without any sanitization or escaping (see the 'Current URL is "%s"' log entry produced by the URL-text display filter in the filter() method). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
CVE-2021-24518 1 Wpfront 1 Notification Bar 2024-11-21 4.8 Medium
The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue