Vulnerabilities (CVE)

Filtered by vendor Smooth Scroll Page Up\/down Buttons Project Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24418 1 Smooth Scroll Page Up\/down Buttons Project 1 Smooth Scroll Page Up\/down Buttons 2024-02-28 3.5 LOW 4.8 MEDIUM
The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_positioning settings, allowing high privilege users such as admin to set an XSS payload in it, which will be executed in all pages of the blog
CVE-2021-24331 1 Smooth Scroll Page Up\/down Buttons Project 1 Smooth Scroll Page Up\/down Buttons 2024-02-28 3.5 LOW 4.8 MEDIUM
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them