Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
duogeek vulnerabilities and exploits
(subscribe to this query)
710
VMScore
CVE-2022-1218
The Domain Replace WordPress plugin up to and including 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Duogeek Domain Replace
710
VMScore
CVE-2021-39313
The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows malicious users to inject arbitrary web scripts, in versions up to and including 1.0.6.
Duogeek Simple Image Gallery
710
VMScore
CVE-2021-39319
The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows malicious users to inject arbitrary web scripts, in versions up to and including 1.4.8.
Duogeek Duofaq-responsive-flat-simple-faq
810
VMScore
CVE-2024-56024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget allows Reflected XSS.This issue affects Custom Dashboard Widget: from n/a up to and including 1.0.0.
Duogeek Custom Dashboard Widget
810
VMScore
CVE-2025-23786
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Email to Download allows Reflected XSS. This issue affects Email to Download: from n/a up to and including 3.1.0.
Duogeek Email To Download
750
VMScore
CVE-2024-51868
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek DuoGeek Blocks allows Stored XSS.This issue affects DuoGeek Blocks: from n/a through .1.
750
VMScore
CVE-2024-51861
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duogeek EventPress allows Stored XSS.This issue affects EventPress: from n/a up to and including 1.0.0.
750
VMScore
CVE-2024-51860
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget allows Stored XSS.This issue affects Custom Dashboard Widget: from n/a up to and including 1.0.0.
750
VMScore
CVE-2024-51618
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DuoGeek Custom Admin Menu allows Stored XSS.This issue affects Custom Admin Menu: from n/a up to and including 1.0.0.
Preferred Score:
VMScore
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
CVE-2024-50264
CVE-2025-43703
wpweb
mass assignment
CVE-2025-32817
CVE-2025-27840
CVE-2025-32844
information disclosure
CVE-2025-31338
woocommerce social login
sonicwall
avb
local
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started