Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.1
LambertGroup LBG Zoominoutslider: Malicious Scripts Can Be Injected into Website
CVE-2026-28103
Summary
The LambertGroup LBG Zoominoutslider plugin for websites has a security flaw that allows malicious code to be injected into a website through user input. This means that if a user visits a website with this plugin installed, they could be tricked into executing malicious code on their browser. To stay safe, website owners should update the plugin to version 5.4.6 or later.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutslider allows Reflected XSS.This issue affects LB...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutslider allows Reflected XSS.This issue affects LBG Zoominoutslider: from n/a through <= 5.4.5.
nvd CVSS3.1
7.1
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026