CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Go-CMS SQL Injection Vulnerability Allowing Arbitrary Code Execution
A SQL injection vulnerability has been identified in Go-CMS version 1.1.10. This vulnerability allows remote attackers to execute arbitrary code by sending a crafted payload. The issue arises when exporting user or role data, as the application improperly concatenates IDs into SQL queries, creating an opportunity for injection.
NodeBB Persistent Cross-Site Scripting Vulnerability
A persistent cross-site scripting vulnerability has been identified in NodeBB version 3.11.0. This vulnerability allows remote attackers to store arbitrary scripts in the 'about me' section of user profiles, which are executed when the profile is viewed by others.
HL7 FHIR IG Publisher Implementation Guide Publisher CLI GitHub Credentials Exposure Vulnerability
A vulnerability exists in the HL7 FHIR IG Publisher prior to version 1.8.9, where the IG Publisher CLI can unintentionally expose GitHub usernames and credentials. This occurs in continuous integration (CI) environments when the tool uses Git commands to fetch the repository URL. If the repository is cloned using a credentials-based URL, the full URL, including sensitive information, is incorporated into the generated Implementation Guide. This issue does not affect users who clone public repositories without credentials, such as those utilizing the auto-ig-build CI infrastructure.
JoeyBling Bootplus Open Redirect Vulnerability in QrCodeController
An open redirect vulnerability has been identified in JoeyBling Bootplus versions prior to commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the qrCode function of the QrCodeController.java file, where the text parameter is not properly validated. This lack of restriction allows attackers to create QR codes that direct users to malicious URLs. The vulnerability can be exploited remotely.
JoeyBling Bootplus Resource Consumption Vulnerability in QrCodeController Allowing Denial-of-Service
A resource consumption vulnerability has been identified in JoeyBling Bootplus versions through commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the qrCode method of the QrCodeController.java file, where the width and height parameters are not properly restricted. This lack of validation can lead to excessive resource usage, causing a denial-of-service condition. The vulnerability can be exploited remotely.
JoeyBling Bootplus Path Traversal Vulnerability in SysFileController
A path traversal vulnerability has been identified in JoeyBling Bootplus versions up to commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the file 'src/main/java/io/github/controller/SysFileController.java', where the download method fails to properly validate the 'name' parameter. This lack of input sanitization allows for the manipulation of file paths, enabling remote attackers to download arbitrary files from the server.
HL7 FHIR IG Publisher XML External Entity Injection Vulnerability
A vulnerability allowing XML external entity (XXE) injection has been identified in the HL7 FHIR IG Publisher tool, in versions prior to 1.7.4. This issue arises from XSLT transformations that can be manipulated with a malicious XML file containing a harmful DTD tag. The exploitation of this vulnerability could lead to the disclosure of data from the host system. This issue is particularly concerning in scenarios where the FHIR IG Publisher is used in an environment that accepts XML submissions from external clients.
WordPress Roi Calculator Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Roi Calculator plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
WordPress PDF Invoices for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress PDF Invoices for WooCommerce plugin, specifically in versions through 4.6.0. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the site.
Kadence WP Gutenberg Blocks Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Kadence WP Gutenberg Blocks plugin, specifically in versions through 3.3.1. This vulnerability allows exploitation of improperly configured access control, potentially enabling users with lower privileges to perform actions reserved for higher privileged users.
GoDaddy CoBlocks Missing Authorization Vulnerability Allowing Access Control Exploitation
A missing authorization vulnerability has been identified in the GoDaddy CoBlocks WordPress plugin, specifically in versions through 3.1.13. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions or access.
ExactMetrics WordPress Plugin Missing Authorization Vulnerability Allowing Broken Access Control
A broken access control vulnerability has been identified in the ExactMetrics WordPress plugin, specifically in versions through 8.1.0. This vulnerability arises from missing authorization checks, which can be exploited by users with lower privileges to perform actions reserved for higher privileged users.
Popup Maker Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Popup Maker WordPress plugin, affecting versions through 1.20.2. This issue allows attackers to inject malicious scripts that are executed when users visit the site.
FluentSMTP WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the FluentSMTP WordPress plugin, specifically in versions through 2.2.80. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
NowButtons.com Call Now Button Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the NowButtons.com Call Now Button plugin for WordPress, specifically in versions through 1.4.13. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Metaphor Creations Post Duplicator Missing Authorization Vulnerability Allowing Access Control Exploitation
A missing authorization vulnerability has been identified in the Metaphor Creations Post Duplicator plugin, affecting versions through 2.35. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.
AddonMaster Post Grid Master Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the AddonMaster Post Grid Master plugin, affecting versions through 3.4.12. This vulnerability arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion.
BookingPress DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the BookingPress WordPress plugin, specifically in versions through 1.1.25. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.
IP2Location Download Country Blocker Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the IP2Location Download IP2Location Country Blocker plugin for WordPress, affecting versions through 2.38.3. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Rextheme WP VR Plugin DOM-Based Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the Rextheme WP VR plugin, affecting versions through 8.5.14. This issue allows for DOM-based XSS, where malicious scripts can be injected and executed in the context of the user's browser.
ElementInvader Addons for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the ElementInvader Addons for Elementor plugin, affecting versions through 1.3.3. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Yannick Lefebvre Bug Library SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the WordPress Bug Library plugin, affecting versions through 2.1.4. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing malicious actors to interact with the database and potentially steal information.
CodePeople Contact Form Email Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the CodePeople Contact Form Email plugin, affecting versions through 1.3.52. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
HT Plugins HT Contact Form 7 Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the HT Contact Form 7 WordPress plugin, affecting versions through 1.2.1. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
ThimPress Thim Elementor Kit Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Thim Elementor Kit WordPress plugin, specifically in versions through 1.2.8. This vulnerability allows exploitation of improperly configured access control, potentially enabling users to perform actions reserved for higher privileges.
WordPress Side Menu Lite Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Side Menu Lite plugin, affecting versions through 5.3.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
CodePeople Booking Calendar Contact Form Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the CodePeople Booking Calendar Contact Form plugin, affecting versions through 1.2.55. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress FAQ Builder AYS Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress FAQ Builder AYS plugin, affecting versions through 1.7.3. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Aleksandar Urošević Easy YouTube Gallery Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Easy YouTube Gallery plugin by Aleksandar Urošević, affecting versions through 1.0.4. This vulnerability allows for the injection of malicious scripts that could be executed when users visit the affected site.
Wow-Company Sticky Buttons WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Sticky Buttons WordPress plugin, affecting versions through 4.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Widget Countdown Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Widget Countdown plugin, affecting versions through 2.7.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Wow-Company Modal Window Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Modal Window plugin for WordPress, affecting versions through 6.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Wow-Company Herd Effects WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Herd Effects WordPress plugin, affecting versions through 6.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Wow-Company Counter Box Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Counter Box WordPress plugin, affecting versions through 2.0.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Bubble Menu Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Bubble Menu – circle floating menu plugin, affecting versions through 4.0.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Button Generator Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Button Generator - Easily Button Builder plugin, affecting versions through 3.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
RadiusTheme Radius Blocks Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the RadiusTheme Radius Blocks plugin for WordPress, affecting versions through 2.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Popup Box Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Popup Box plugin, specifically in versions through 3.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Plethora Plugins Tabs + Accordions Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress plugin Plethora Plugins Tabs + Accordions, affecting versions through 1.1.5. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
MultiVendorX WC Marketplace Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the MultiVendorX WC Marketplace plugin for WordPress, affecting versions through 4.2.13. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Arshid WooCommerce Quick View Missing Authorization Vulnerability Allowing Sensitive Data Exposure
A missing authorization vulnerability in the Arshid WooCommerce Quick View plugin, affecting versions through 1.1.1, allows exploitation of improperly configured access control. This vulnerability could lead to unauthorized exposure of sensitive data that regular users typically cannot access.
WordPress Magic the Gathering Card Tooltips Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Magic the Gathering Card Tooltips plugin, affecting versions through 3.4.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
WordPress DLX Plugins Comment Edit Core Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in the WordPress Comment Edit Core – Simple Comment Editing plugin, affecting versions through 3.0.33. This vulnerability allows attackers to manipulate the server into making requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
Xagio SEO Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Xagio SEO WordPress plugin, affecting versions through 7.0.0.20. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Kiboko Labs Chained Quiz Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in the Kiboko Labs Chained Quiz WordPress plugin, affecting versions through 1.3.2.9. This vulnerability allows attackers to manipulate the server into making requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
G5Theme Essential Real Estate Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the G5Theme Essential Real Estate WordPress plugin, affecting versions through 5.1.8. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WP Attire Attire Blocks Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Attire Attire Blocks plugin, affecting versions through 1.9.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
HasThemes Extensions For CF7 Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in HasThemes Extensions For CF7, affecting versions through 3.2.0. This vulnerability allows attackers to make the server send requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
Yehi Advanced Notifications Plugin Missing Authorization Vulnerability Allowing Access Control Exploitation
A missing authorization vulnerability has been identified in the Yehi Advanced Notifications WordPress plugin, specifically in versions through 1.2.7. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions or changes.
WordPress People Lists Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress People Lists plugin, affecting versions through 1.3.10. This vulnerability arises from missing authorization checks, allowing unprivileged users to exploit incorrectly configured access control security levels.
