Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
get custom field values project get custom field values vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2021-24871
The Get Custom Field Values WordPress plugin prior to 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks
Get Custom Field Values Project Get Custom Field Values
4.8
CVSSv3
CVE-2023-45604
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Reilly Get Custom Field Values plugin <= 4.0.1 versions.
Get Custom Field Values Project Get Custom Field Values
6.5
CVSSv3
CVE-2021-24872
The Get Custom Field Values WordPress plugin prior to 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.
Get Custom Field Values Project Get Custom Field Values
NA
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 prior to 3.4.5 allows remote malicious users to execute arbitrary SQL commands via the list[select] parameter to index.php.
Joomla Joomla\\! 3.2.0
Joomla Joomla\\! 3.2.1
Joomla Joomla\\! 3.3.4
Joomla Joomla\\! 3.4.0
Joomla Joomla\\! 3.3.2
Joomla Joomla\\! 3.3.3
Joomla Joomla\\! 3.2.4
Joomla Joomla\\! 3.3.0
Joomla Joomla\\! 3.3.1
Joomla Joomla\\! 3.4.3
Joomla Joomla\\! 3.4.4
Joomla Joomla\\! 3.2.2
Joomla Joomla\\! 3.2.3
Joomla Joomla\\! 3.4.1
Joomla Joomla\\! 3.4.2
1 EDB exploit
14 Github repositories
1 Article
NA
CVE-2015-7858
SQL injection vulnerability in Joomla! 3.2 prior to 3.4.4 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297.
Joomla Joomla\\! 3.4.0
Joomla Joomla\\! 3.3.3
Joomla Joomla\\! 3.3.4
Joomla Joomla\\! 3.3.1
Joomla Joomla\\! 3.3.2
Joomla Joomla\\! 3.2.4
Joomla Joomla\\! 3.4.3
Joomla Joomla\\! 3.3.0
Joomla Joomla\\! 3.2.2
Joomla Joomla\\! 3.2.3
Joomla Joomla\\! 3.4.2
Joomla Joomla\\! 3.4.1
Joomla Joomla\\! 3.2.0
Joomla Joomla\\! 3.2.1
1 EDB exploit
14 Github repositories
1 Article
NA
CVE-2015-7297
SQL injection vulnerability in Joomla! 3.2 prior to 3.4.4 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.
Joomla Joomla\\! 3.2.1
Joomla Joomla\\! 3.2.2
Joomla Joomla\\! 3.3.4
Joomla Joomla\\! 3.4.0
Joomla Joomla\\! 3.2.0
Joomla Joomla\\! 3.3.2
Joomla Joomla\\! 3.3.3
Joomla Joomla\\! 3.3.0
Joomla Joomla\\! 3.3.1
Joomla Joomla\\! 3.4.4
Joomla Joomla\\! 3.2.3
Joomla Joomla\\! 3.2.4
Joomla Joomla\\! 3.4.1
Joomla Joomla\\! 3.4.2
Joomla Joomla\\! 3.4.3
1 EDB exploit
14 Github repositories
1 Article
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
client side
CVE-2023-31889
template injection
CVE-2024-4304
CVE-2006-4304
CVE-2024-33272
type confusion
CVE-2024-21345
CVE-2024-33271
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started