| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal hosts and services, including requests with an attacker-chosen method, headers and body. |
| The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the ProSolution WP Client WordPress plugin before 2.0.9's activity records. |
| SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password. |
| A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system. |
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. |
| Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. |
| Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. |
| Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. |
| Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. |
| Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. |
| Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. |
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. |