Search Results (35 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-37227 1 Tribulant 1 Newsletters 2026-02-27 4.3 Medium
Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.
CVE-2023-4797 1 Tribulant 1 Newsletters 2025-06-11 7.2 High
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
CVE-2014-5460 1 Tribulant 1 Tibulant Slideshow Gallery 2025-04-12 N/A
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.
CVE-2024-35718 1 Tribulant 1 Newsletters 2024-11-21 7.1 High
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.5.
CVE-2023-28497 1 Tribulant 1 Slideshow Gallery 2024-11-21 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions.
CVE-2021-24882 1 Tribulant 1 Slideshow Gallery 2024-11-21 4.8 Medium
The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
CVE-2020-35932 1 Tribulant 1 Newsletter 2024-11-21 7.5 High
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.
CVE-2019-15828 1 Tribulant 1 One Click Ssl 2024-11-21 N/A
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.
CVE-2019-14788 1 Tribulant 1 Newsletters 2024-11-21 8.8 High
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
CVE-2019-14787 1 Tribulant 1 Newsletters 2024-11-21 5.4 Medium
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
CVE-2018-20987 1 Tribulant 1 Newsletters 2024-11-21 N/A
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
CVE-2018-18019 1 Tribulant 1 Slideshow Gallery 2024-11-21 N/A
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.
CVE-2018-18018 1 Tribulant 1 Slideshow Gallery 2024-11-21 N/A
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
CVE-2018-18017 1 Tribulant 1 Slideshow Gallery 2024-11-21 N/A
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
CVE-2018-17946 1 Tribulant 1 Slideshow Gallery 2024-11-21 N/A
The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.