Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2022-29435

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to delete or to turn on/off snippets.
Attacker Value
Unknown

CVE-2022-29436

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code).
Attacker Value
Unknown

CVE-2022-29429

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery.
Attacker Value
Unknown

CVE-2021-25008

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2020-8417

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.