Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kibokolabs vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2022-4212
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ipf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possi...
Kibokolabs Chained Quiz
6.1
CVSSv3
CVE-2023-4602
The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated malicious...
Kibokolabs Namaste\\! Lms
6.1
CVSSv3
CVE-2023-30483
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3.3.9.2 versions.
Kibokolabs Watu Quiz
6.1
CVSSv3
CVE-2016-10892
The chained-quiz plugin prior to 1.0 for WordPress has multiple XSS issues.
Kibokolabs Chained Quiz
9.8
CVSSv3
CVE-2015-10111
A vulnerability was found in Watu Quiz Plugin up to 2.6.7 on WordPress. It has been rated as critical. This issue affects the function watu_exams of the file controllers/exam.php of the component Exam Handler. The manipulation of the argument quiz leads to sql injection. The atta...
Kibokolabs Watu Quiz
9.8
CVSSv3
CVE-2018-14502
controllers/quizzes.php in the Kiboko Chained Quiz plugin prior to 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
Kibokolabs Chained Quiz
6.1
CVSSv3
CVE-2023-0428
The Watu Quiz WordPress plugin prior to 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Kibokolabs Watu Quiz
4.8
CVSSv3
CVE-2023-0429
The Watu Quiz WordPress plugin prior to 3.3.8.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite ...
Kibokolabs Watu Quiz
4.8
CVSSv3
CVE-2023-0548
The Namaste! LMS WordPress plugin prior to 2.5.9.4 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisi...
Kibokolabs Namaste\\! Lms
4.8
CVSSv3
CVE-2023-0844
The Namaste! LMS WordPress plugin prior to 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite s...
Kibokolabs Namaste\\! Lms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »