CVE-2020-36510: Codetipi 15zine
Medium severity, CVSS 6.1. EPSS: 2.6% chance of exploitation in the next 30 days.
The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the response via the cb_s_a AJAX action, leading to a Reflected Cross-Site Scripting
Affected products
- Codetipi 15zine: before 3.3.0 (fixed in 3.3.0)
Published 2022-02-28. Last modified 2026-06-17.