CVE-2011-4969medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inj
CVE-2019-16780medium · CVSS 5.8 — WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is
CVE-2022-3590medium · CVSS 5.9 — WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation ch