SlimStat Analytics <= 5.3.5 - Unauthenticated Stored Cross-Site Scripting via 'fh'
SlimStat Analytics
Minimum safe version
5.4.0
Update to 5.4.0 or later to address 37 fixable vulnerabilities
CVE-2025-69323
CVE-2025-13431
CVE-2025-15055
CVE-2025-15057
CVE-2025-14151
CVE-2024-9548
CVE-2024-1073
WordPress Slimstat Analytics Plugin <= 5.1.3 is vulnerable to Cross Site Scripting (XSS)
SlimStat Analytics <= 5.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting
CVE-2023-4598
CVE-2023-4597
CVE-2023-40676
CVE-2023-33994
WP SlimStat 2.8.4 - wp-content/plugins/wp-slimstat/admin/view/panel1.php s Parameter XSS
WP Slimstat <= 3.9.5 - Weak Cryptographic Keys Leading to SQL Injections
WP Slimstat <= 4.8.3 - CSRF to Stored XSS and Setting Updates
Slimstat Analytics < 4.9.4 - Subscriber+ SQL Injection
CVE-2022-45373
CVE-2022-45366
WordPress Slimstat Analytics Plugin < 4.9.4 is vulnerable to SQL Injection
WordPress Slimstat Analytics Plugin <= 4.9.3.3 is vulnerable to SQL Injection
Slimstat Analytics <= 4.9.3.3 - Authenticated (Subscriber+) SQL Injection via Shortcode
CVE-2023-0630
Slimstat Analytics < 3.9.6 - Unauthenticated Blind SQL Injection
Slimstat Analytics <= 4.8.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVE-2022-4310
Slimstat Analytics <= 4.9.2 - Reflected Cross-Site Scripting via REQUEST_URI
WordPress Slimstat Plugin <= 3.9.5 - SQL Injections
WordPress SlimStat Plugin <= 2.8.4 - Cross Site Scripting
WordPress Slimstat Plugin <= 4.1.5.2 - Cross Site Scripting
WordPress Slimstat plugin <= 4.8 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress Slimstat Analytics plugin <= 4.8.3 - Cross-Site Request Forgery (CSRF) to Stored Cross-Site Scripting (XSS) + Setting Updates vulnerabilities
CVE-2014-100027
CVE-2015-1204
CVE-2015-9273
CVE-2019-15112