Latest CVE Feed
-
5.4
MEDIUMCVE-2023-0945
A vulnerability, which was classified as problematic, was found in SourceCodester Best POS Management System 1.0. Affected is an unknown function of the file index.php?page=add-category. The manipulation of the argument Name with the input "><img src=x on... Read more
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0726
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticate... Read more
Affected Products : wicked_folders- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0685
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthent... Read more
Affected Products : wicked_folders- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0725
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticat... Read more
Affected Products : wicked_folders- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0708
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with con... Read more
Affected Products : metform_elementor_contact_form_builder- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0728
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticate... Read more
Affected Products : wicked_folders- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0610
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.... Read more
Affected Products : wallabag- Published: Feb. 01, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0723
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticate... Read more
Affected Products : wicked_folders- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0709
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with cont... Read more
Affected Products : metform_elementor_contact_form_builder- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0719
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscr... Read more
Affected Products : wicked_folders- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0660
The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above... Read more
Affected Products : smart_slider_3- Published: Mar. 27, 2023
- Modified: Feb. 19, 2025
-
5.4
MEDIUMCVE-2023-0684
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subsc... Read more
Affected Products : wicked_folders- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0559
The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above... Read more
Affected Products : gs_portfolio_for_envato- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2023-0540
The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to... Read more
Affected Products : gs_filterable_portfolio- Published: Feb. 21, 2023
- Modified: Mar. 13, 2025
-
5.4
MEDIUMCVE-2023-0552
The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability... Read more
Affected Products : pie_register- Published: Feb. 27, 2023
- Modified: Mar. 18, 2025
-
5.4
MEDIUMCVE-2023-0717
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscrib... Read more
Affected Products : wicked_folders- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0727
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthentica... Read more
Affected Products : wicked_folders- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0549
A vulnerability, which was classified as problematic, has been found in YAFNET up to 3.1.10. This issue affects some unknown processing of the file /forum/PostPrivateMessage of the component Private Message Handler. The manipulation of the argument subjec... Read more
Affected Products : yaf.net- Published: Jan. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0492
The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role a... Read more
Affected Products : gs_products_slider- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2023-0403
The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.0. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it possible for unauthenticated attackers... Read more
Affected Products : social_warfare- Published: Jan. 19, 2023
- Modified: Nov. 21, 2024