Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
book vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2021-24538
The Current Book WordPress plugin up to and including 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.
Current Book Project Current Book
NA
CVE-2006-6764
PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote malicious users to execute arbitrary PHP code via a URL in the default_path_to_themes parameter.
Keep It Simple Guest Book Keep It Simple Guest Book 5.0
Keep It Simple Guest Book Keep It Simple Guest Book
1 EDB exploit
NA
CVE-2008-2566
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.
Php-address Book Php-address Book
2 EDB exploits
5.4
CVSSv3
CVE-2023-1126
The WP FEvents Book WordPress plugin up to and including 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks
Wp Fevents Book Project Wp Fevents Book
6.5
CVSSv3
CVE-2023-1129
The WP FEvents Book WordPress plugin up to and including 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.
Wp Fevents Book Project Wp Fevents Book
4.3
CVSSv3
CVE-2022-1842
The OpenBook Book Data WordPress plugin up to and including 3.5.2 does not have CSRF check in place when updating its settings, which could allow malicious users to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of san...
Openbook Book Data Project Openbook Book Data
NA
CVE-2006-4575
Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote malicious users to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) n...
The Address Book The Address Book 1.04e
NA
CVE-2007-1059
PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote malicious users to execute arbitrary PHP code via a URL in the gbpfad parameter. NOTE: some sources mention "Ultimate Fun Board," but this appears to be an error.
Ultimate Fun Book Ultimate Fun Book 1.02
1 EDB exploit
9.8
CVSSv3
CVE-2012-6652
Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.
Page Flip Book Project Page Flip Book -
NA
CVE-2006-4576
Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote malicious users to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG extension, which is rendered by Internet Explorer.
The Address Book The Address Book 1.04e
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »