Search Results (24 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-41657 1 Groundhogg 1 Hollerbox 2024-11-21 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. HollerBox plugin <= 2.3.2 versions.
CVE-2023-40681 1 Groundhogg 1 Groundhogg 2024-11-21 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11.10 versions.
CVE-2023-34179 1 Groundhogg 1 Groundhogg 2024-11-21 7.2 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Inc. Groundhogg allows SQL Injection.This issue affects Groundhogg: from n/a through 2.7.11.
CVE-2019-15647 1 Groundhogg 1 Groundhogg 2024-11-21 N/A
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.