Security Advisories

TitleCVE ID
Actueel Financieel Nieuws – Denk Internet Solutions <= 5.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settingsCVE-2023-47554
Download CloudNet360 <= 3.2.0 - Reflected Cross-Site ScriptingCVE-2023-46643
Pressference Exporter <= 1.0.3 - Authenticated (Administrator+) SQL InjectionCVE-2023-45046
Cookies by JM <= 1.0 - Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-40604
CT Commerce <= 2.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via admin settingsCVE-2023-40007
WP Default Feature Image <= 1.0.1.1 - Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-25488
Reservation.Studio widget <= 1.0.11 - Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-24397
WP-Piwik <= 1.0.27 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Display NameCVE-2023-33211
SEO Change Monitor <= 1.2 - Authenticated (Subscriber+) SQL InjectionCVE-2023-33209
Sloth Logo Customizer <= 2.0.2 - Cross-Site Request Forgery to Stored Cross-Site ScriptingCVE-2023-0603
Simple Custom Author Profiles <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-24372
WP Simple Events <= 1.0 - Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-24376
Tags Cloud Manager <= 1.0.0 - Reflected Cross-Site ScriptingCVE-2023-28166
Easy Event calendar <= 1.0 - Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-28169
CC Custom Taxonomy <= 1.0.1 - Authenticated (Administrator+) Cross-Site ScriptingCVE-2023-25028
Marketing Performance <= 2.0.0 - Unauthenticated Stored Cross-Site ScriptingCVE-2023-24404
WP Food Manager <= 1.0.3 - Authenticated(Administrator+) Stored Cross-Site ScriptingCVE-2023-0604
Cross-site Scripting (XSS) - Stored in microweber/microweberCVE-2022-0379
Cross-site Scripting (XSS) - Stored in microweber/microweberCVE-2022-0558
Business Logic Errors in microweber/microweberCVE-2022-0688
Memory corruption / Integer Overflow in microweber/microweberCVE-2022-1036
HTML Injection vulnerability in create tag functionality in microweber/microweberCVE-2022-3245
Origin validation Bypass in ikus060/rdiffwebCVE-2022-3457