Skip to content

Known CVE

Header Footer Code Manager < 1.1.24 - Cross-Site Scripting

The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-0899

Medium2022CVSS 6.1CWE-79

cve2022 · wpscan · wp · wp-plugin · wordpress · xss · authenticated · draftpress

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website