
CVE-2025-26538 – WordPress Prezi Embedder plugin <= 2.1 - Stored Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2025-26538
13 Feb 2025 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Prezi Embedder allows Stored XSS. This issue affects Prezi Embedder: from n/a through 2.1. The Prezi Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script... • https://patchstack.com/database/wordpress/plugin/prezi-embedder/vulnerability/wordpress-prezi-embedder-plugin-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-17137
https://notcve.org/view.php?id=CVE-2018-17137
17 Sep 2018 — Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might allow attackers to bypass intended access restrictions. Prezi Next 1.3.101.11 tiene el propósito documentado de crear presentaciones HTML5, pero tiene SE_DEBUG_PRIVILEGE en Windows, lo que podría permitir que los atacantes omitan las restricciones de acceso planeadas. • https://github.com/GitHubAssessments/CVE_Assessment_04_2018 •