Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Clickbank_affiliate_ads
(Cbads)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-12-02 | CVE-2015-20106 | The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | Clickbank_affiliate_ads | 4.8 | ||
2021-12-02 | CVE-2015-20105 | The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues | Clickbank_affiliate_ads | 9.6 |