<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Robo</title>
  <link>https://cvedaily.com/pages/tags/robo.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/robo.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Robo</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:57 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-4300 – The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4300</guid>
    <pubDate>Wed, 08 Apr 2026 10:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4300</strong></p>
  <p>The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in all versions up to, and including, 5.1.3. The plugin uses a custom `|***...***|` marker pattern in its `fixJsFunction()` method to embed raw JavaScript function references within JSON-encoded configuration objects. When a gallery's options are rendered on the frontend, `json_encod…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32356 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32356</guid>
    <pubDate>Fri, 13 Mar 2026 19:54:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32356</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows DOM-Based XSS.This issue affects Robo Gallery: from n/a through <= 5.1.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14306 – A directory traversal vulnerability exists in the CacheCleaner component of Robo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14306</guid>
    <pubDate>Tue, 09 Dec 2025 16:17:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14306</strong></p>
  <p>A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47521 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47521</guid>
    <pubDate>Wed, 07 May 2025 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47521</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through <= 5.0.2.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54392 – Cross-Site Request Forgery (CSRF) vulnerability in midoks WP微信机器人 wp-weixin-robo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54392</guid>
    <pubDate>Mon, 16 Dec 2024 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54392</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in midoks WP微信机器人 wp-weixin-robot allows Stored XSS.This issue affects WP微信机器人: from n/a through <= 5.3.5.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-45841 – Missing Authorization vulnerability in RoboSoft Robo Gallery allows Exploiting I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45841</guid>
    <pubDate>Fri, 13 Dec 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-45841</strong></p>
  <p>Missing Authorization vulnerability in RoboSoft Robo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robo Gallery: from n/a through 3.2.9.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-49696 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49696</guid>
    <pubDate>Thu, 24 Oct 2024 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-49696</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through <= 3.2.21.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34382 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Robo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34382</guid>
    <pubDate>Mon, 06 May 2024 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34382</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RoboSoft Robo Gallery.This issue affects Robo Gallery: from n/a through 3.2.18.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-12968 – A vulnerability was found in the Sonic Robo Blast 2 (SRB2) plugin (EP_Versions 9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12968</guid>
    <pubDate>Wed, 26 Jun 2019 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-12968</strong></p>
  <p>A vulnerability was found in the Sonic Robo Blast 2 (SRB2) plugin (EP_Versions 9 to 11 inclusive) distributed with Doomseeker 1.1 and 1.2. Affected plugin versions did not discard IP packets with an unnaturally long response length from a Sonic Robo Blast 2 master server, allowing a remote attacker to cause a potential crash / denial of service in Doomseeker. The issue has been remediated in the…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-4095 – Directory traversal vulnerability in the FTP client in Serengeti Systems Incorpo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4095</guid>
    <pubDate>Tue, 26 Oct 2010 20:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-4095</strong></p>
  <p>Directory traversal vulnerability in the FTP client in Serengeti Systems Incorporated Robo-FTP 3.7.3, and probably other versions before 3.7.5, allows remote FTP servers to write arbitrary files via a .. (dot dot) in a filename in a server response.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-4103 – Buffer overflow in Robo-FTP 3.6.17, and possibly other versions, allows remote F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4103</guid>
    <pubDate>Sun, 29 Nov 2009 13:08:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-4103</strong></p>
  <p>Buffer overflow in Robo-FTP 3.6.17, and possibly other versions, allows remote FTP servers to cause a denial of service and possibly execute arbitrary code via unspecified FTP server responses.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-3068 – Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3068</guid>
    <pubDate>Fri, 04 Sep 2009 18:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-3068</strong></p>
  <p>Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vd_adobe module in…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3068">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
