| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. |
| A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato. |
| Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. |
| SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data. |
| The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, so a cross-user read is not achievable by guessing alone. |
| Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. |
| Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. |
| Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. |
| The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. |
| Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. |
| Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. |