CVE Browser
Podlove Podcast Publisher <= 4.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter
Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload
Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function
Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name
Archivist – Custom Archive Templates <= 1.7.5 - Reflected Cross-Site Scripting
Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Unauthenticated Data Export
Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Settings Import
Showing 1 to 9 CVEs · page 1