cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2022-0210,https://securityvulnerability.io/vulnerability/CVE-2022-0210,Random Banner <= 4.1.4 Admin+ Stored Cross-Site Scripting,"The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.",Wordpress,Random Banner,4.8,MEDIUM,0.0006500000017695129,false,,false,false,false,,false,false,2022-01-18T16:52:30.000Z,0 CVE-2014-4847,https://securityvulnerability.io/vulnerability/CVE-2014-4847,,Cross-site scripting (XSS) vulnerability in the Random Banner plugin 1.1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the buffercode_RBanner_url_banner1 parameter in an update action to wp-admin/options.php.,Wordpress,Random Banner,,,0.002050000010058284,false,,false,false,false,,false,false,2014-07-10T16:00:00.000Z,0