Authenticated (Contributor+) DOMBased Stored CrossSite Scripting via heading Parameter vulnerability
13 January, 2025
Missing Authorization in multiple functions via h5vp_ajax_handler vulnerability
11 September, 2024
Missing Authorization to Authenticated (Subscriber+) Limited Options Update vulnerability
11 September, 2024
Sensitive Data Exposure vulnerability
16 August, 2024
Broken Access Control vulnerability
16 August, 2024