S4E just found a low-severity finding from dns a record lookup
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2023-2272

6.1
CVSS
Description

The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Attack Vector
-
Privileges Req.
-
User Interaction
-
tiempo.com
Updated Sep 22, 2026View on NVD →
S4E scanner

CVE history: tiempo.com

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →