Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Haofanjiukunle

#21553of 56,330
12.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-84115
6.4
2026-09-01
WordPress · Blocksy Companion · CVE-2026-18488
**Name of the Vulnerable Software and Affected Versions** Blocksy Companion versions prior to 2.1.52 **Description** Insufficient input sanitization and output escaping in the `tagName` block attribute (blocksy/dynamic-data) allow authenticated attackers with author-level access or higher to perform Stored Cross-Site Scripting. This enables the injection of arbitrary web scripts into pages, which execute when a user visits the affected page. **Recommendations** Update Blocksy Companion to version 2.1.52 or later.
PT-2026-68405
6.4
2026-08-06
Metaslider · Slider · CVE-2026-18400
**Name of the Vulnerable Software and Affected Versions** Slider, Gallery, and Carousel by MetaSlider versions prior to 3.111.1 **Description** Insufficient input sanitization and output escaping allow authenticated attackers with Author-level access and above to perform Stored Cross-Site Scripting. This occurs because the `ml-slider` custom post type lacks custom capability restrictions and the `ml-slider settings` meta key is unprotected. An attacker can inject arbitrary web scripts by setting a malicious value for the `delay` parameter via XML-RPC `custom fields` when creating an `ml-slider` post. These scripts execute whenever a user accesses the affected page. **Recommendations** Update to a version newer than 3.111.0.