Vulnerabilities (CVE)

Filtered by vendor Stock In \& Out Project Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24346 1 Stock In \& Out Project 1 Stock In \& Out 2024-02-28 3.5 LOW 5.4 MEDIUM
The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being contributor. The srch POST parameter is not validated, sanitised or escaped before using it in the echo statement, leading to a reflected XSS issue