Skip to content

Known CVE

Prismatic < 2.8 - Cross-Site Scripting

The plugin does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

CVE-2021-24409

Medium2021CVSS 6.1CWE-79

cve2021 · wpscan · wordpress · wp · wp-plugin · xss · prismatic · authenticated

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website