November 5, 2024 at 2:39 am
Hi!
At least two sites I built and using Kadence Blocks, a Vulnerability report from the webost in Denmark/sweden One.com shows up after some time. Useally after a few months to half a year. I dont know why this time table seem to be so consistent, but thats not the issue. The issue of being that Kadence Blocks are reported as vulnerable.
So, below is the report I recieve in the email inbox from the webhost One.com
(Kadence team: see in private comment a link to one of the websites)
” -Vulnerabilities:
Kadence Blocks – Gutenberg Blocks for Page Builder Features v3.2.52Medium
XXS errors occur whenever an app contains untrusted data in a new web page without proper validation or leakage, or updates an existing web page with user-supplied data using a browser’s API to generate HTML or JavaAScript. XSS allows hackers to execute scripts in the victim’s browser, which can hijack sessions, deform websites, or redirect the user to malicious sites. ”
Any knowledge to share on why and what this can be causing this vulnerability?
Best regards
Stefan L