| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. |
| The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. |
| Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. |
| Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. |
| Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. |
| Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. |
| Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. |
| Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. |
| Contributor Local File Inclusion in Vino <= 1.9 versions. |
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. |
| Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. |
| Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. |
| Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. |
| Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12. |