Home/Product/themepunch slider revolution
Product

themepunch slider revolution

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-8107
<= 6.7.18
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to
6.4MEDIUM
CVE-2024-37449
< 6.7.14
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider
5.9MEDIUM
CVE-2024-34444
< 6.7.0
Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.
7.1HIGH
CVE-2024-34443
< 6.7.11
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider
5.9MEDIUM
CVE-2024-4637
< 6.7.11
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.
6.4MEDIUM
CVE-2024-4581
< 6.7.11
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all v
6.4MEDIUM
CVE-2024-4092
< 6.7.8
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all ver
6.4MEDIUM
CVE-2023-6528
< 6.6.19
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbit
8.8HIGH
CVE-2023-47784
<= 6.6.15
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolu
8.4HIGH
CVE-2023-47772
<= 6.6.14
Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14.
6.5MEDIUM
CVE-2023-2359
<= 6.6.12
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary fi
8.8HIGH
CVE-2015-5151
all versions
Cross-site scripting (XSS) vulnerability in the Slider Revolution (revslider) plugin 4.2.2 for WordPress allows remote attackers t
CVE-2014-9735
<= 3.0.95
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordp
CVE-2014-9734
<= 4.1.4
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to
threatengine.sh