Vulnerabilities (CVE)

Filtered by vendor Sandhillsdev Subscribe
Filtered by product Easy Digital Downloads
Total 45 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9516 2 Easydigitaldownloads, Sandhillsdev 2 Invoices, Easy Digital Downloads 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9529 2 Easydigitaldownloads, Sandhillsdev 2 Stripe, Easy Digital Downloads 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9520 2 Easydigitaldownloads, Sandhillsdev 2 Per Product Emails, Easy Digital Downloads 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Per Product Emails extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9324 1 Sandhillsdev 1 Easy Digital Downloads 2023-12-10 7.5 HIGH 9.8 CRITICAL
The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
CVE-2019-15116 1 Sandhillsdev 1 Easy Digital Downloads 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.