CVEFinder.io

CVE-2021-34630

đŸ”ļ medium
🔍 Scan for this CVE
Summary

In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where

Description

In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where the user is using an atypical browsing solution.

CVSS Score
5.0
Medium
EPSS Score
4.5
Exploit Probability
Published Date
2021-07-30
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 19.3% of all 329,456 vulnerabilities in our database.

#265,985
Below average severity
Severity Percentile
Last Modified 2024-11-21
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 1

đŸ’Ŗ Public Exploits 1 PRO

Loading exploits...

Loading exploit information...

🔗 References 1

🔗 Related CVEs 1

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-8492 â„šī¸ low 2.7 0.0 Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource L... 2026-05-19
These CVEs affect the same products