cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forfast-flow-dashboard fast-flow-dashboard

Direction: ascending
Jun 07, 2024

Fast Flow # CVE-2022-2775

CVE, Research URL

CVE-2022-2775

Application

Fast Flow

Date
Sep 05, 2022
Research Description
The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 1.2.13.
Status
vulnerable

Fast Flow # CVE-2022-1269

CVE, Research URL

CVE-2022-1269

Application

Fast Flow

Date
May 02, 2022
Research Description
The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting
Affected versions
max 1.2.11.
Status
vulnerable
Feb 26, 2025

Fast Flow # CVE-2025-26868

CVE, Research URL

CVE-2025-26868

Application

Fast Flow

Date
Feb 25, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fastflow Fast Flow fast-flow-dashboard allows Reflected XSS.This issue affects Fast Flow: from n/a through <= 1.2.16.
Affected versions
max 1.2.18.
Status
vulnerable
Jun 16, 2026

Fast Flow # 9ce0b3bcd6337203a7615f024751226aa761fa98

Application

Fast Flow

Date
Aug 15, 2022
Research Description
Fast Flow [fast-flow-dashboard] < 1.2.12 Fast Flow <= 1.2.11 - Reflected Cross-Site Scripting The Fast Flow WordPress plugin is vulnerable to reflected Cross-Site scripting in versions up to, and including, 1.2.11, via the 'p' parameter due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.2.12.
Status
vulnerable

Fast Flow # ca9267d0-9dea-4cd1-9795-06922286497d

Application

Fast Flow

Date
-
Research Description
Fast Flow [fast-flow-dashboard] < 1.2.12 Fast Flow &lt; 1.2.12 - Reflected Cross-Site Scripting The plugin does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
Affected versions
max 1.2.12.
Status
vulnerable