| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. |
| Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. |
| Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. |
| Subscriber Broken Authentication in Leyka <= 3.32.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. |
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. |
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. |
| Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. |
| Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. |
| Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. |
| Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. |
| Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. |
| Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects New User Approve: from n/a through 3.2.8. |
| The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address. |
| Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. |
| Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection.
This issue affects TaxoPress: from n/a through 3.51.0. |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection.
This issue affects InfiniteWP Client: from n/a through 1.13.9. |