Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57816 2 Funnelkit, Wordpress 2 Funnel Builder By Funnelkit, Wordpress 2026-07-13 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8.
CVE-2025-10567 2 Funnelkit, Wordpress 2 Funnel Builder, Wordpress 2026-04-15 6.3 Medium
The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.