Skip to content
Noroxi

nextendweb records

10 published records for vendor nextendweb.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
20%
Median publish → KEV
No record has entered KEV

All records

10 records
  • CVE-2024-9893
    39Monitor

    Nextend Social Login Pro <= 3.1.14 - Authentication Bypass via WordPress.com OAuth provider

    CriticalCVSS 9.8No exploitEPSS 1%

    nextendweb · nextend social login proOct 16, 2024

  • CVE-2022-3357
    36Monitor

    Smart Slider 3 < 3.5.1.11 - PHP Object Injection

    HighCVSS 8.8Proof of conceptEPSS 2%

    nextendweb · smart slider 3Oct 31, 2022

  • WordPress Smart Slider 3 Plugin <= 3.5.1.9 is vulnerable to PHP Object Injection

    HighCVSS 8.8No exploitEPSS 1%

    nextendweb · smart slider 3Jan 19, 2024

  • CVE-2015-4557
    25Monitor

    Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Conne

    MediumCVSS 6.1No exploitEPSS 2%

    nextendweb · nextend twitter connectApr 12, 2018

  • Smart Slider 3 < 3.5.0.9 - Authenticated Stored Cross-Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 1%

    nextendweb · smart sliderJun 14, 2021

  • CVE-2023-0660
    21Monitor

    Smart Slider 3 < 3.5.1.14 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 0%

    nextendweb · smart slider 3Mar 27, 2023

  • WordPress Smart Slider 3 Plugin <= 3.5.1.9 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    nextendweb · smart slider 3Mar 23, 2023

  • CVE-2024-1775
    21Monitor

    Nextend Social Login and Register <= 3.1.12 - Reflected Self-Based Cross-Site Scripting via error_description

    MediumCVSS 5.4No exploitEPSS 0%

    nextendweb · nextend social loginMar 2, 2024

  • CVE-2014-8800
    18Monitor

    Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress

    MediumCVSS 4.3Proof of conceptEPSS 4%

    nextendweb · nextend facebook connectDec 5, 2014

  • CVE-2015-4413
    18Monitor

    Cross-site scripting (XSS) vulnerability in the new_fb_sign_button function in nextend-facebook-connect.php in Nextend Facebook Connect plug

    MediumCVSS 4.3No exploitEPSS 3%

    nextendweb · facebook connectJun 24, 2015