cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-11447,https://securityvulnerability.io/vulnerability/CVE-2024-11447,Unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability in Community by PeepSo,"The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up to, and including, 6.4.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",Wordpress,Community By Peepso – Download From Peepso.com,6.1,MEDIUM,0.0005200000014156103,false,,false,false,false,,,false,false,,2024-11-21T02:06:18.381Z,0 CVE-2024-9873,https://securityvulnerability.io/vulnerability/CVE-2024-9873,Sweden's Ruling Party Backs Investigative Journalist Over Government Censorship Claims,"The Community by PeepSo plugin for WordPress is exposed to a Stored Cross-Site Scripting vulnerability due to insufficient sanitization of inputs and escaping of outputs. When Markdown support is enabled, authenticated users with Subscriber-level access or higher can exploit this flaw by injecting malicious scripts into posts, comments, and profiles. These scripts can execute in the browsers of users accessing the affected pages, posing a serious risk to user data integrity and security.",Wordpress,"Community By Peepso – Social Network, Membership, Registration, User Profiles, Premium – Mobile App",5.4,MEDIUM,0.0004299999854993075,false,,false,false,false,,,false,false,,2024-10-16T05:31:56.035Z,0 CVE-2024-7618,https://securityvulnerability.io/vulnerability/CVE-2024-7618,Stored Cross-Site Scripting vulnerability in PeepSo's Social Network plugin,"The PeepSo plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) attacks due to a lack of sufficient input sanitization and output escaping in the 'content' parameter. This vulnerability affects all versions of the plugin up to and including version 6.4.5.0 and can be exploited by authenticated attackers with administrator-level access. When triggered, the vulnerability allows attackers to embed malicious scripts in web pages, which execute whenever any user accesses those affected pages. The risk is elevated in multi-site installations and configurations where the unfiltered_html option is disabled, increasing the potential for unauthorized script execution.",Wordpress,"Community By Peepso – Social Network, Membership, Registration, User Profiles, Premium – Mobile App",4.8,MEDIUM,0.0006099999882280827,false,,false,false,false,,,false,false,,2024-09-10T07:30:04.499Z,0 CVE-2024-7655,https://securityvulnerability.io/vulnerability/CVE-2024-7655,Stored Cross-Site Scripting Vulnerability Affects PeepSo Community Multi-Site Installations,"The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.",Wordpress,"Community By Peepso – Social Network, Membership, Registration, User Profiles, Premium – Mobile App",4.8,MEDIUM,0.0006099999882280827,false,,false,false,false,,,false,false,,2024-09-10T07:30:03.793Z,0 CVE-2023-7125,https://securityvulnerability.io/vulnerability/CVE-2023-7125,Community by PeepSo < 6.3.1.2 - User Post Creation via CSRF,"The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack",Wordpress,Community by PeepSo,4.3,MEDIUM,0.000539999979082495,false,,false,false,true,2024-01-16T15:57:04.000Z,true,false,false,,2024-01-16T15:57:04.740Z,0 CVE-2024-0187,https://securityvulnerability.io/vulnerability/CVE-2024-0187,Community by PeepSo < 6.3.1.2 - Reflected XSS,"The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin",Wordpress,Community By Peepso,6.1,MEDIUM,0.0006600000197067857,false,,false,false,true,2024-01-16T15:57:01.000Z,true,false,false,,2024-01-16T15:57:01.019Z,0