cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foryoutube-embed youtube-embed

Direction: ascending
Jun 06, 2024

YouTube Embed # CVE-2021-24471

CVE, Research URL

CVE-2021-24471

Application

YouTube Embed

Date
Aug 16, 2021
Research Description
The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, leading to Stored XSS issues by 1. using w, h, controls, cc_lang, color, language, start, stop, or style parameter of youtube shortcode, 2. by using style, class, rel, target, width, height, or alt parameter of youtube_thumb shortcode, or 3. by embedding a video whose title or description contains XSS payload (if API key is configured).
Affected versions
Min -, max -.
Status
vulnerable

YouTube Embed # CVE-2015-6535

CVE, Research URL

CVE-2015-6535

Application

YouTube Embed

Date
Aug 31, 2015
Research Description
Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).
Affected versions
Min -, max -.
Status
vulnerable
Apr 11, 2025

YouTube Embed # CVE-2025-31008

CVE, Research URL

CVE-2025-31008

Application

YouTube Embed

Date
Apr 09, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YouTube Embed Plugin Support YouTube Embed allows Stored XSS. This issue affects YouTube Embed: from n/a through 5.3.1.
Affected versions
Min -, max -.
Status
vulnerable