Vulnerabilities (CVE)

Filtered by vendor Quotes Llama Project Subscribe
Filtered by product Quotes Llama
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1566 1 Quotes Llama Project 1 Quotes Llama 2024-11-21 3.5 LOW 4.8 MEDIUM
The Quotes llama WordPress plugin through 0.7 does not sanitise and escape Quotes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. The attack could also be performed by tricking an admin to import a malicious CSV file