11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-4899
SEOPress Web Windows
5.0
MEDIUM
EPSS
0.2%
2024 1 PoC

The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CVE-2024-9102
phpLDAPadmin Web Windows
5.0
MEDIUM
EPSS
0.1%
2024 CWE-1236 1 PoC

phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory into a Comma-Separated Value (CSV) file, but it does not neutralize special elements that could be interpreted as a command when the file is opened by a spreadsheet product. Thus, this could lead to CSV Formula Injection. NOTE: This vulnerability will not be addressed, the maintainer's position is that it is not the intention of phpLDAPadmin to control what data Administrators can put in their LDAP database, nor filter it on export.

CVE-2022-4154
Contest Gallery Pro Web Database Windows
4.9
MEDIUM
EPSS
0.8%
2022 2 PoCs

The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVE-2020-14869
MySQL Server Database Windows
4.9
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2025-14719
Relevanssi Web Database Windows
4.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

CVE-2025-10046
ELEX WooCommerce Google Shopping (Google Product Feed) Web Database Windows
4.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' parameter in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-3471
SureForms Web Windows
4.9
MEDIUM
EPSS
0.2%
2025 1 PoC

The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action

CVE-2025-12630
Upload.am Web Windows
4.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

CVE-2023-7247
Login as User or Customer Web Windows
4.9
MEDIUM
EPSS
0.3%
2023 2 PoCs

The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.

CVE-2023-3814
Advanced File Manager Web Windows
4.9
MEDIUM
EPSS
0.2%
2023 1 PoC

The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.

CVE-2025-9345
File Manager, Code Editor, and Backup by Managefy Web Windows
4.9
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory.

CVE-2015-10146
Thumbnail Slider With Lightbox Web Database Windows
4.9
MEDIUM
EPSS
0.0%
2015 CWE-89 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-3470
TS Poll – Survey, Versus Poll, Image Poll, Video Poll Web Database Windows
4.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-3279
WordPress Gallery Plugin Web Windows
4.9
MEDIUM
EPSS
1.1%
2023 1 PoC

The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks

CVE-2022-4157
Contest Gallery Web Database Windows
4.9
MEDIUM
EPSS
0.8%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_option_id POST parameter before concatenating it to an SQL query in export-votes-all.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVE-2024-3112
Quotes and Tips by BestWebSoft Web Windows
4.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2021-28200
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28198
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28195
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28207
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.4%
2021 CWE-22 1 PoC

The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.