Home/Product/tagdiv composer
Product

tagdiv composer

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-2806
< 5.4
The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘
6.1MEDIUM
CVE-2025-3510
< 5.4.1
The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up t
6.4MEDIUM
CVE-2024-5212
< 5.1
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in
6.1MEDIUM
CVE-2024-3886
< 5.1
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in
6.1MEDIUM
CVE-2024-3814
< 4.9
The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all vers
5.5MEDIUM
CVE-2024-3813
< 4.9
The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the '
8.8HIGH
CVE-2023-39166
< 4.4
Cross-Site Request Forgery (CSRF) vulnerability in tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tag
7.1HIGH
CVE-2023-3170
< 4.2
The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not val
4.8MEDIUM
CVE-2023-3169
< 4.2
The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not hav
6.1MEDIUM
CVE-2023-1596
< 4.0
The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, le
6.1MEDIUM
CVE-2022-3477
< 3.5
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme
9.8CRITICAL
threatengine.sh