tagDiv records
20 published records for vendor tagdiv.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-269 Improper Privilege Management2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2016-10972Proof of concept | The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.tagdiv · newspaper · CWE-269 | Critical9.8 | — | 9.3% | Sep 16, 2019 |
40Plan | CVE-2017-18634No exploit | The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.tagdiv · newspaper · CWE-74 | Critical9.8 | — | 2.2% | Sep 16, 2019 |
35Monitor | CVE-2024-3813No exploit | tagDiv Composer <= 4.8 - Authenticated (Contributor+) Local File Inclusion via Shortcodetagdiv · tagdiv composer · CWE-98 | High8.8 | — | 0.7% | Jun 14, 2024 |
35Monitor | CVE-2023-1597No exploit | tagDiv Cloud Library < 2.7 - Unauthenticated Arbitrary User Metadata Update to Privilege Escalationtagdiv · cloud library · CWE-269 | High8.8 | — | 0.5% | Jul 10, 2023 |
28Monitor | CVE-2023-3416No exploit | tagDiv Opt-In Builder <= 1.4.4 - Authenticated (Admin+) SQL Injectiontagdiv · tagdiv opt-in builder · CWE-89 | High7.2 | — | 0.6% | Aug 17, 2024 |
28Monitor | CVE-2023-3419No exploit | tagDiv Opt-In Builder <= 1.4.4 - Authenticated (Admin+) SQL Injectiontagdiv · tagdiv opt-in builder · CWE-89 | High7.2 | — | 0.6% | Aug 17, 2024 |
24Monitor | CVE-2023-3169Proof of concept | tagDiv Composer < 4.2 - Unauthenticated Stored XSStagdiv · tagdiv composer · CWE-79 | Medium6.1 | — | 1.3% | Sep 11, 2023 |
24Monitor | CVE-2021-24304No exploit | Newsmag < 5.0 - Unauthenticated Reflected Cross-site Scripting (XSS)tagdiv · newsmag · CWE-79 | Medium6.1 | — | 1.2% | Aug 9, 2021 |
24Monitor | CVE-2022-2627Proof of concept | Newspaper < 12 - Reflected Cross-Site Scriptingtagdiv · newspaper · CWE-79 | Medium6.1 | — | 1.1% | Oct 31, 2022 |
24Monitor | CVE-2021-3135No exploit | An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress.tagdiv · newspaper · CWE-79 | Medium6.1 | — | 0.8% | Jul 19, 2021 |
24Monitor | CVE-2022-2167No exploit | Newspaper < 12 - Reflected Cross-Site Scriptingtagdiv · newspaper · CWE-79 | Medium6.1 | — | 0.6% | Oct 31, 2022 |
24Monitor | CVE-2023-1596No exploit | tagDiv Composer < 4.0 - Reflected Cross-site Scriptingtagdiv · composer · CWE-79 | Medium6.1 | — | 0.5% | May 15, 2023 |
24Monitor | CVE-2024-3886No exploit | tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]tagdiv · tagdiv composer · CWE-79 | Medium6.1 | — | 0.4% | Aug 31, 2024 |
24Monitor | CVE-2024-5212No exploit | tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]tagdiv · tagdiv composer · CWE-79 | Medium6.1 | — | 0.4% | Aug 31, 2024 |
24Monitor | CVE-2025-2806No exploit | tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'data'tagdiv · tagdiv composer · CWE-79 | Medium6.1 | — | 0.3% | May 8, 2025 |
24Monitor | CVE-2023-39166No exploit | WordPress tagDiv Composer Plugin < 4.4 is vulnerable to Cross Site Request Forgery (CSRF)tagdiv · tagdiv composer · CWE-352 | Medium6.1 | — | 0.2% | Nov 13, 2023 |
21Monitor | CVE-2025-3510No exploit | tagDiv Composer <= 5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodestagdiv · composer · CWE-79 | Medium5.4 | — | 0.3% | May 2, 2025 |
19Monitor | CVE-2023-3170No exploit | tagDiv Composer < 4.2 - Admin+ Stored XSStagdiv · tagdiv composer · CWE-79 | Medium4.8 | — | 0.4% | Sep 11, 2023 |
19Monitor | CVE-2024-3815No exploit | Newspaper <= 12.6.5 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Metatagdiv · newspaper · CWE-79 | Medium4.8 | — | 0.3% | Jun 14, 2024 |
19Monitor | CVE-2024-3814No exploit | tagDiv Composer <= 4.8 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Metatagdiv · tagdiv composer · CWE-79 | Medium4.8 | — | 0.3% | Jun 14, 2024 |
- CVE-2016-1097242Plan
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
CriticalCVSS 9.8Proof of conceptEPSS 9%tagdiv · newspaperSep 16, 2019
- CVE-2017-1863440Plan
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
CriticalCVSS 9.8No exploitEPSS 2%tagdiv · newspaperSep 16, 2019
- CVE-2024-381335Monitor
tagDiv Composer <= 4.8 - Authenticated (Contributor+) Local File Inclusion via Shortcode
HighCVSS 8.8No exploitEPSS 1%tagdiv · tagdiv composerJun 14, 2024
- CVE-2023-159735Monitor
tagDiv Cloud Library < 2.7 - Unauthenticated Arbitrary User Metadata Update to Privilege Escalation
HighCVSS 8.8No exploitEPSS 0%tagdiv · cloud libraryJul 10, 2023
- CVE-2023-341628Monitor
tagDiv Opt-In Builder <= 1.4.4 - Authenticated (Admin+) SQL Injection
HighCVSS 7.2No exploitEPSS 1%tagdiv · tagdiv opt-in builderAug 17, 2024
- CVE-2023-341928Monitor
tagDiv Opt-In Builder <= 1.4.4 - Authenticated (Admin+) SQL Injection
HighCVSS 7.2No exploitEPSS 1%tagdiv · tagdiv opt-in builderAug 17, 2024
- CVE-2023-316924Monitor
tagDiv Composer < 4.2 - Unauthenticated Stored XSS
MediumCVSS 6.1Proof of conceptEPSS 1%tagdiv · tagdiv composerSep 11, 2023
- CVE-2021-2430424Monitor
Newsmag < 5.0 - Unauthenticated Reflected Cross-site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 1%tagdiv · newsmagAug 9, 2021
- CVE-2022-262724Monitor
Newspaper < 12 - Reflected Cross-Site Scripting
MediumCVSS 6.1Proof of conceptEPSS 1%tagdiv · newspaperOct 31, 2022
- CVE-2021-313524Monitor
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress.
MediumCVSS 6.1No exploitEPSS 1%tagdiv · newspaperJul 19, 2021
- CVE-2022-216724Monitor
Newspaper < 12 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%tagdiv · newspaperOct 31, 2022
- CVE-2023-159624Monitor
tagDiv Composer < 4.0 - Reflected Cross-site Scripting
MediumCVSS 6.1No exploitEPSS 1%tagdiv · composerMay 15, 2023
- CVE-2024-388624Monitor
tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]
MediumCVSS 6.1No exploitEPSS 0%tagdiv · tagdiv composerAug 31, 2024
- CVE-2024-521224Monitor
tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]
MediumCVSS 6.1No exploitEPSS 0%tagdiv · tagdiv composerAug 31, 2024
- CVE-2025-280624Monitor
tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'data'
MediumCVSS 6.1No exploitEPSS 0%tagdiv · tagdiv composerMay 8, 2025
- CVE-2023-3916624Monitor
WordPress tagDiv Composer Plugin < 4.4 is vulnerable to Cross Site Request Forgery (CSRF)
MediumCVSS 6.1No exploitEPSS 0%tagdiv · tagdiv composerNov 13, 2023
- CVE-2025-351021Monitor
tagDiv Composer <= 5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes
MediumCVSS 5.4No exploitEPSS 0%tagdiv · composerMay 2, 2025
- CVE-2023-317019Monitor
tagDiv Composer < 4.2 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%tagdiv · tagdiv composerSep 11, 2023
- CVE-2024-381519Monitor
Newspaper <= 12.6.5 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta
MediumCVSS 4.8No exploitEPSS 0%tagdiv · newspaperJun 14, 2024
- CVE-2024-381419Monitor
tagDiv Composer <= 4.8 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta
MediumCVSS 4.8No exploitEPSS 0%tagdiv · tagdiv composerJun 14, 2024