Vulnerabilities and security researches forfast-flow-dashboard fast-flow-dashboard
Direction: ascendingJun 07, 2024
Fast Flow # CVE-2022-2775
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 05, 2022
- Research Description
- The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
max 1.2.13.
- Status
-
vulnerable
Fast Flow # CVE-2022-1269
- CVE, Research URL
- Home page URL
- Application
- Date
- May 02, 2022
- Research Description
- The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting
- Affected versions
-
max 1.2.11.
- Status
-
vulnerable
Feb 26, 2025
Fast Flow # CVE-2025-26868
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 25, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fastflow Fast Flow fast-flow-dashboard allows Reflected XSS.This issue affects Fast Flow: from n/a through <= 1.2.16.
- Affected versions
-
max 1.2.18.
- Status
-
vulnerable
Jun 16, 2026
Fast Flow # 9ce0b3bcd6337203a7615f024751226aa761fa98
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 15, 2022
- Research Description
- Fast Flow [fast-flow-dashboard] < 1.2.12 Fast Flow <= 1.2.11 - Reflected Cross-Site Scripting The Fast Flow WordPress plugin is vulnerable to reflected Cross-Site scripting in versions up to, and including, 1.2.11, via the 'p' parameter due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.2.12.
- Status
-
vulnerable
Fast Flow # ca9267d0-9dea-4cd1-9795-06922286497d
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Fast Flow [fast-flow-dashboard] < 1.2.12 Fast Flow < 1.2.12 - Reflected Cross-Site Scripting The plugin does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected versions
-
max 1.2.12.
- Status
-
vulnerable