| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4. |
| A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory. |
| Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions. |
| Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions. |
| Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions. |
| Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1. |
| Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions. |
| Shop Manager Privilege Escalation in Challan <= 3.7.88 versions. |
| Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. |
| Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions. |
| Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions. |
| Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions. |
| Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions. |
| Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions. |
| Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. |
| Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions. |
| Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions. |
| Editor Remote Code Execution (RCE) in Tabs <= 2.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor & Themes <= 2.1.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions. |