Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
login vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2024-24712
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a up to and including 1.1.30.
Heateor Social Login
4.3
CVSSv2
CVE-2018-1000173
A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized malicious users to impersonate another user if they can control the pre-authentication session.
Jenkins Google Login
7.5
CVSSv2
CVE-2007-4342
PHP remote file inclusion vulnerability in include.php in PHPCentral Login 1.0 allows remote malicious users to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. NOTE: a third party disputes this vulnerability because of the special nature of the SERVE...
Phpcentral Login 1.0
NA
CVE-2023-22958
The Syracom Secure Login plugin prior to 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter.
Syracom Secure Login
NA
CVE-2022-4838
The Clean Login WordPress plugin prior to 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used aga...
Codection Clean Login
3.5
CVSSv2
CVE-2020-24723
Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.
User Registration \\& Login And User Management System Project User Registration \\& Login And User Management System 2.1
7.5
CVSSv2
CVE-2020-25952
SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote malicious users to execute arbitrary SQL commands and bypass authentication.
User Registration \\& Login And User Management System Project User Registration \\& Login And User Management System 2.1
1 Github repository
NA
CVE-2023-33591
User Registration & Login and User Management System v1.0 exists to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.
User Registration \\& Login And User Management System Project User Registration \\& Login And User Management System 1.0
NA
CVE-2023-47806
Cross-Site Request Forgery (CSRF) vulnerability in Saint Systems Disable User Login.This issue affects Disable User Login: from n/a up to and including 1.3.7.
Saintsystems Disable User Login
4.3
CVSSv2
CVE-2017-8875
CSRF in the Clean Login plugin prior to 1.8 for WordPress allows remote malicious users to change the login redirect URL or logout redirect URL.
Codection Clean Login 1.7.12
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
spoof
CVE-2024-34928
CVE-2024-5291
deserialization
CVE-2024-4471
CVE-2024-4956
CVE-2024-32002
CVE-2024-5227
unspecified
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »