| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files.
This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43. |
| Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe. |
| Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. |
| Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions. |
| Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. |
| Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. |
| Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. |
| Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. |
| Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. |
| Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. |
| Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. |
| Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. |
| Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. |
| Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. |
| Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. |
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. |
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. |
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. |
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. |
| The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or . |