Medium 6.1
2026-04-11< 4.2.4
Optimole <= 4.2.3 - Reflected Cross-Site Scripting via Page Profiler URL
Minimum safe version
4.2.4
Update to 4.2.4 or later to address 5 fixable vulnerabilities
Optimole <= 4.2.3 - Reflected Cross-Site Scripting via Page Profiler URL
Optimole <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter
CVE-2025-11519
CVE-2024-4636
CVE-2022-0969