<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – tarteaucitron</title>
  <link>https://cvedaily.com/pages/tags/tarteaucitron.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/tarteaucitron.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – tarteaucitron</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:01 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-22809 – tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22809</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22809</strong></p>
  <p>tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (ReDoS) vulnerability was identified in tarteaucitron.js in the handling of the issuu_id parameter. This vulnerability is fixed in 1.29.0.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48939 – tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48939</guid>
    <pubDate>Thu, 03 Jul 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48939</strong></p>
  <p>tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element, it could clobber the document.currentScript property. This causes the script to resolve incorrectly to an element…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-138</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-4955 – The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from Yo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4955</guid>
    <pubDate>Wed, 18 Jun 2025 06:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-4955</strong></p>
  <p>The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11719 – The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11719</guid>
    <pubDate>Thu, 15 May 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11719</strong></p>
  <p>The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11718 – The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11718</guid>
    <pubDate>Thu, 15 May 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11718</strong></p>
  <p>The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-31476 – tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31476</guid>
    <pubDate>Mon, 07 Apr 2025 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-31476</strong></p>
  <p>tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a mal…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-31475 – tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31475</guid>
    <pubDate>Mon, 07 Apr 2025 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-31475</strong></p>
  <p>tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such a…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-31138 – tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31138</guid>
    <pubDate>Mon, 07 Apr 2025 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-31138</strong></p>
  <p>tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set values like 100%;height:100%;position:fixed;, potentially covering the entir…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3620 – Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3620</guid>
    <pubDate>Tue, 11 Jul 2023 15:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3620</strong></p>
  <p>Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-33155 – The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33155</guid>
    <pubDate>Tue, 12 Jul 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-33155</strong></p>
  <p>The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows XSS.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-36889 – Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36889</guid>
    <pubDate>Mon, 20 Dec 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-36889</strong></p>
  <p>Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6).</p>
  <p><strong>CVSS:</strong> 3.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36887 – Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36887</guid>
    <pubDate>Mon, 20 Dec 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36887</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass".</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36887">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
