Known Vulnerabilities for EWWW Image Optimizer by Nosilver4u
Listed below are 7 of the newest known vulnerabilities associated with "EWWW Image Optimizer" by "Nosilver4u".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-97067 json | Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-92826 json | The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key i... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-91072 json | The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the curre... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-91051 json | The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions fro... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-91011 json | The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page ... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-84773 json | Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-15446 json | The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attrib... | Not Provided | 2026-08-19 | 2026-08-20 |