Authenticated (Author+) Stored CrossSite Scripting via SVG File Upload vulnerability
11 April, 2025
Authenticated (Subscriber+) Stored CrossSite Scripting via SVG File Upload vulnerability
8 April, 2025
Cross Site Request Forgery (CSRF) Vulnerability
4 April, 2025
Authenticated (Subscriber+) SQL Injection via orderby Parameter vulnerability
14 February, 2025
Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update vulnerability
14 February, 2025