Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 1.5 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2016-10762
The CampTix Event Ticketing plugin prior to 1.5 for WordPress allows CSV injection when the export tool is used.
Automattic Camptix Event Ticketing
7.5
CVSSv3
CVE-2017-1002004
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
Dtracker Project Dtracker 1.5
7.5
CVSSv3
CVE-2017-1002005
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.
Dtracker Project Dtracker 1.5
7.5
CVSSv3
CVE-2017-1002006
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
Dtracker Project Dtracker 1.5
7.5
CVSSv3
CVE-2017-1002007
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
Dtracker Project Dtracker 1.5
7.2
CVSSv3
CVE-2016-10939
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
Xtremelocator Xtremelocator 1.5
7
CVSSv3
CVE-2017-2624
It was found that xorg-x11-server prior to 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is...
X.org Xorg-server
Debian Debian Linux 7.0
1 Github repository
6.5
CVSSv3
CVE-2021-24820
The Cost Calculator WordPress plugin up to and including 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout
Bold-themes Cost Calculator
6.5
CVSSv3
CVE-2021-24795
The Filter Portfolio Gallery WordPress plugin up to and including 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow malicious users to make a logged in admin delete arbitrary Gallery.
Phoeniixx Filter Portfolio Gallery
6.5
CVSSv3
CVE-2015-9447
The unite-gallery-lite plugin prior to 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
Unitegallery Unite Gallery Lite
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »