VendorsVektor Incvk_all_in_one_expansion_unitall versions
Vulnerabilities

Vektor Inc Vector Inc VK All in One Expansion Unit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-2093
VK All in One Expansion Unit <= 9.95.0.1 - Information Exposure
Published 2024-04-09 · Modified
6.5EPSS 0.007
CVE-2024-37956
WordPress VK All in One Expansion Unit plugin <= 9.99.1.0 - Cross Site Scripting (XSS) vulnerability
Published 2024-07-20 · Modified
6.5EPSS 0.003
CVE-2024-2170
VK All in One Expansion Unit <= 9.96.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via className
Published 2024-03-26 · Modified
6.4EPSS 0.003
CVE-2023-0937
VK All in One Expansion Unit < 9.87.1.0 - Reflected XSS
Published 2023-03-20 · Modified
6.1EPSS 0.005
CVE-2023-27926
Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
Published 2023-05-23 · Modified
5.4EPSS 0.006
CVE-2023-28367
Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
Published 2023-05-23 · Modified
5.4EPSS 0.006
CVE-2023-0230
VK All in One Expansion Unit < 9.86.0.0 - Contributor+ Stored XSS
Published 2023-02-27 · Modified
5.4EPSS 0.006
CVE-2024-52268
Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing the web site using the product.
Published 2024-11-13 · Analyzed
4.8EPSS 0.003