Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
duogeek vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2022-1218
The Domain Replace WordPress plugin up to and including 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Duogeek Domain Replace
6.1
CVSSv3
CVE-2021-39313
The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows malicious users to inject arbitrary web scripts, in versions up to and including 1.0.6.
Duogeek Simple Image Gallery
6.1
CVSSv3
CVE-2021-39319
The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows malicious users to inject arbitrary web scripts, in versions up to and including 1.4.8.
Duogeek Duofaq-responsive-flat-simple-faq
7.1
CVSSv3
CVE-2024-56024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget allows Reflected XSS.This issue affects Custom Dashboard Widget: from n/a up to and including 1.0.0.
Duogeek Custom Dashboard Widget
7.1
CVSSv3
CVE-2025-23786
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Email to Download allows Reflected XSS. This issue affects Email to Download: from n/a up to and including 3.1.0.
Duogeek Email To Download
6.5
CVSSv3
CVE-2024-51868
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek DuoGeek Blocks allows Stored XSS.This issue affects DuoGeek Blocks: from n/a through .1.
6.5
CVSSv3
CVE-2024-51861
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duogeek EventPress allows Stored XSS.This issue affects EventPress: from n/a up to and including 1.0.0.
6.5
CVSSv3
CVE-2024-51860
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget allows Stored XSS.This issue affects Custom Dashboard Widget: from n/a up to and including 1.0.0.
6.5
CVSSv3
CVE-2024-51618
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DuoGeek Custom Admin Menu allows Stored XSS.This issue affects Custom Admin Menu: from n/a up to and including 1.0.0.
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
physical
picture gallery
CVE-2025-30352
administrator privileges
gdpr tools
CVE-2025-26007
CVE-2025-24514
CVE-2025-26581
CVE-2025-1098
wp multistore locator
CVE-2025-26986
nous ouvert utile et simple
command injection
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started