Majeedraza's vulnerability profile centers on a carousel slider component, a focused web-development offering whose exposure recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, and missing authorization. These input-handling and access-control issues are characteristic of client-side web components and reflect the intersection of DOM manipulation and trust boundaries in interactive UI libraries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Majeedraza over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4372MEDIUM The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scriptin | May 21, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-41848MEDIUM Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from | Dec 13, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-3703MEDIUM The Carousel Slider WordPress plugin before 2.2.10 does not validate and escape some of its Slide options before outputting them back in the page/post where the related Slide short | May 3, 2024 | 4.7 | 16 | NO | NO |
CVE-2024-1712MEDIUM The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Si | Apr 15, 2024 | 4.7 | 16 | NO | NO |
CVE-2024-6850MEDIUM The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Sc | Sep 13, 2024 | 4.8 | 15 | NO | NO |
CVE-2024-45270MEDIUM WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress si | Sep 2, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-45269MEDIUM WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPres | Sep 2, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Majeedraza.
Media articles that mention a CVE ID that affects a product developed by Majeedraza — matched by CVE ID, not by vendor name.