Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-56006 2 H5p, Wordpress 2 H5p, Wordpress 2026-06-26 7.1 High
Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
CVE-2025-68505 2 H5p, Wordpress 2 H5p, Wordpress 2026-04-27 5.3 Medium
Missing Authorization vulnerability in icc0rz H5P h5p allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects H5P: from n/a through <= 1.16.1.
CVE-2024-3111 1 H5p 1 H5p 2024-11-21 5.4 Medium
The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and above to update malicious SVG files, leading to Stored Cross-Site Scripting issues