Maxfoundry / Maxbuttons
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-39444 | WordPress MaxButtons plugin <= 9.8.3 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 5.9 | Apr 17, 2025 |
| CVE-2024-8968 | MaxButtons < 9.8.1 - Admin+ Stored XSS via Text Color | MEDIUM | 4.7 | Dec 20, 2024 |
| CVE-2024-10555 | MaxButtons < 9.8.1 - Admin+ Stored XSS via Button Width | MEDIUM | 4.8 | Dec 20, 2024 |
| CVE-2024-6499 | WordPress Button Plugin MaxButtons <= 9.7.8 - Full Path Disclosure | MEDIUM | 5.3 | Aug 24, 2024 |
| CVE-2024-3026 | WordPress Button Plugin MaxButtons < 9.7.8 - Editor+ Stored XSS | MEDIUM | 5.4 | Jul 13, 2024 |
| CVE-2023-7029 | WordPress Button Plugin MaxButtons <= 9.7.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode | MEDIUM | 6.4 | Feb 5, 2024 |
| CVE-2023-6594 | WordPress Button Plugin MaxButtons <= 9.7.4 - Authenticated (Administrator+) Stored Cross-Site Scripting | MEDIUM | 4.8 | Jan 9, 2024 |
| CVE-2023-36503 | WordPress MaxButtons Plugin <= 9.5.3 is vulnerable to Cross Site Scripting (XSS) | MEDIUM | 6.5 | Jul 25, 2023 |
| CVE-2014-125092 | MaxButtons Plugin maxbuttons-button.php maxbuttons_strip_px cross site scripting | MEDIUM | 6.1 | Mar 5, 2023 |
| CVE-2022-38703 | WordPress Button Plugin MaxButtons plugin <= 9.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | MEDIUM | 4.8 | Sep 23, 2022 |
| CVE-2022-36346 | WordPress MaxButtons plugin <= 9.2 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities | HIGH | 8.8 | Aug 22, 2022 |
| CVE-2017-2169 | Cross-site scripting vulnerability in MaxButtons prior to version 6.19 and MaxButtons Pro prior to version 6.19 allows remote attackers to inject arbitrary web… | MEDIUM | 6.1 | May 22, 2017 |
| CVE-2014-7181 | Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote attackers to inject arbitrary web scrip… | MEDIUM | 4.3 | Oct 16, 2014 |
Showing 1 to 11 of 11 CVEs