Known Vulnerabilities for products from Optiontree Project
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Optiontree Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-15321 json | The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. | 9.8 - CRITICAL | 2019-08-22 | 2020-08-24 |
| CVE-2019-15320 json | The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. | 9.8 - CRITICAL | 2019-08-22 | 2020-08-24 |
| CVE-2019-15319 json | The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. | 9.8 - CRITICAL | 2019-08-22 | 2020-08-24 |
| CVE-2016-10895 json | The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request. | 6.1 - MEDIUM | 2019-08-20 | 2019-08-22 |
| CVE-2015-9320 json | The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg. | 6.1 - MEDIUM | 2019-08-20 | 2023-02-24 |
Known software with vulnerabilities from Optiontree Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Optiontree Project | Optiontree | 1.0.0 |