Skip to content
Noroxi

tagDiv records

20 published records for vendor tagdiv.

All records

20 records
  • The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    tagdiv · newspaperSep 16, 2019

  • The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.

    CriticalCVSS 9.8No exploitEPSS 2%

    tagdiv · newspaperSep 16, 2019

  • CVE-2024-3813
    35Monitor

    tagDiv Composer <= 4.8 - Authenticated (Contributor+) Local File Inclusion via Shortcode

    HighCVSS 8.8No exploitEPSS 1%

    tagdiv · tagdiv composerJun 14, 2024

  • CVE-2023-1597
    35Monitor

    tagDiv Cloud Library < 2.7 - Unauthenticated Arbitrary User Metadata Update to Privilege Escalation

    HighCVSS 8.8No exploitEPSS 0%

    tagdiv · cloud libraryJul 10, 2023

  • CVE-2023-3416
    28Monitor

    tagDiv Opt-In Builder <= 1.4.4 - Authenticated (Admin+) SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    tagdiv · tagdiv opt-in builderAug 17, 2024

  • CVE-2023-3419
    28Monitor

    tagDiv Opt-In Builder <= 1.4.4 - Authenticated (Admin+) SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    tagdiv · tagdiv opt-in builderAug 17, 2024

  • CVE-2023-3169
    24Monitor

    tagDiv Composer < 4.2 - Unauthenticated Stored XSS

    MediumCVSS 6.1Proof of conceptEPSS 1%

    tagdiv · tagdiv composerSep 11, 2023

  • Newsmag < 5.0 - Unauthenticated Reflected Cross-site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 1%

    tagdiv · newsmagAug 9, 2021

  • CVE-2022-2627
    24Monitor

    Newspaper < 12 - Reflected Cross-Site Scripting

    MediumCVSS 6.1Proof of conceptEPSS 1%

    tagdiv · newspaperOct 31, 2022

  • CVE-2021-3135
    24Monitor

    An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress.

    MediumCVSS 6.1No exploitEPSS 1%

    tagdiv · newspaperJul 19, 2021

  • CVE-2022-2167
    24Monitor

    Newspaper < 12 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    tagdiv · newspaperOct 31, 2022

  • CVE-2023-1596
    24Monitor

    tagDiv Composer < 4.0 - Reflected Cross-site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    tagdiv · composerMay 15, 2023

  • CVE-2024-3886
    24Monitor

    tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]

    MediumCVSS 6.1No exploitEPSS 0%

    tagdiv · tagdiv composerAug 31, 2024

  • CVE-2024-5212
    24Monitor

    tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]

    MediumCVSS 6.1No exploitEPSS 0%

    tagdiv · tagdiv composerAug 31, 2024

  • CVE-2025-2806
    24Monitor

    tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'data'

    MediumCVSS 6.1No exploitEPSS 0%

    tagdiv · tagdiv composerMay 8, 2025

  • WordPress tagDiv Composer Plugin < 4.4 is vulnerable to Cross Site Request Forgery (CSRF)

    MediumCVSS 6.1No exploitEPSS 0%

    tagdiv · tagdiv composerNov 13, 2023

  • CVE-2025-3510
    21Monitor

    tagDiv Composer <= 5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes

    MediumCVSS 5.4No exploitEPSS 0%

    tagdiv · composerMay 2, 2025

  • CVE-2023-3170
    19Monitor

    tagDiv Composer < 4.2 - Admin+ Stored XSS

    MediumCVSS 4.8No exploitEPSS 0%

    tagdiv · tagdiv composerSep 11, 2023

  • CVE-2024-3815
    19Monitor

    Newspaper <= 12.6.5 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta

    MediumCVSS 4.8No exploitEPSS 0%

    tagdiv · newspaperJun 14, 2024

  • CVE-2024-3814
    19Monitor

    tagDiv Composer <= 4.8 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta

    MediumCVSS 4.8No exploitEPSS 0%

    tagdiv · tagdiv composerJun 14, 2024