Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 1.0.1 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2012-6628
Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin prior to 1.0.2 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) xyz_em_campName to admin/create_campaign.php or (2) admin/edit_campaign.php, (3) xyz_e...
Xyzscripts Newsletter Manager 1.0
Xyzscripts Newsletter Manager
Xyzscripts Newsletter Manager 1.0.1
6.8
CVSSv2
CVE-2012-6629
Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin 1.0.2 and previous versions for WordPress allow remote malicious users to hijack the authentication of administrators for requests that (1) change an email address or (2) conduct script in...
Xyzscripts Newsletter Manager
Xyzscripts Newsletter Manager 1.0.1
Xyzscripts Newsletter Manager 1.0
2.6
CVSSv2
CVE-2013-4954
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin prior to 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote malicious users to inject arbitrary web scrip...
Genetechsolutions Pie-register 1.2.9
Genetechsolutions Pie-register 1.2.1
Genetechsolutions Pie-register 1.2.0
Genetechsolutions Pie-register 1.1.3
Genetechsolutions Pie-register 1.1.2
Genetechsolutions Pie-register 1.2.91
Genetechsolutions Pie-register 1.2.3
Genetechsolutions Pie-register 1.2.2
Genetechsolutions Pie-register 1.1.6
Genetechsolutions Pie-register 1.1.5
Genetechsolutions Pie-register 1.2.6
Genetechsolutions Pie-register 1.2.4
Genetechsolutions Pie-register 1.1.8
Genetechsolutions Pie-register 1.1.7
Genetechsolutions Pie-register 1.2.8
Genetechsolutions Pie-register 1.2.7
Genetechsolutions Pie-register 1.1.9
Genetechsolutions Pie-register 1.1.1
Genetechsolutions Pie-register 1.0.1
Genetechsolutions Pie-register
1 EDB exploit
4.3
CVSSv2
CVE-2011-3858
Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme prior to 2.1.6 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the s parameter.
Zespia Pixiv Custom
Zespia Pixiv Custom 1.0
Zespia Pixiv Custom 1.0.1
Zespia Pixiv Custom 1.0.2
Zespia Pixiv Custom 1.1
Zespia Pixiv Custom 1.1.1
Zespia Pixiv Custom 1.1.2
Zespia Pixiv Custom 1.1.3
Zespia Pixiv Custom 1.1.4
Zespia Pixiv Custom 1.1.5
Zespia Pixiv Custom 1.1.6
Zespia Pixiv Custom 1.1.7
Zespia Pixiv Custom 1.1.9
Zespia Pixiv Custom 1.1.10
Zespia Pixiv Custom 1.1.11
Zespia Pixiv Custom 1.1.12
Zespia Pixiv Custom 1.1.13
Zespia Pixiv Custom 1.1.14
Zespia Pixiv Custom 1.2.0
Zespia Pixiv Custom 1.2.1
Zespia Pixiv Custom 1.3.0
Zespia Pixiv Custom 1.3.1
1 EDB exploit
4.3
CVSSv2
CVE-2008-1502
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare prior to 1.4.003, Moodle prior to 1.8.5, and other products, allows remote malicious users to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string contai...
Moodle Moodle 1.8.1
Moodle Moodle 1.6.7
Moodle Moodle 1.5.0
Moodle Moodle 1.5.3
Moodle Moodle 1.4.2
Moodle Moodle 1.4.1
Moodle Moodle 1.2.0
Moodle Moodle 1.1.1
Moodle Moodle
Moodle Moodle 1.7.4
Moodle Moodle 1.7.3
Moodle Moodle 1.6.4
Moodle Moodle 1.6.3
Moodle Moodle 1.6.2
Moodle Moodle 1.5
Moodle Moodle 1.4.5
Moodle Moodle 1.3.2
Moodle Moodle 1.3.1
Egroupware Egroupware 1.0.3
Egroupware Egroupware 1.0.1
Moodle Moodle 1.7.6
Moodle Moodle 1.7.5
4.3
CVSSv2
CVE-2013-3262
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin prior to 3.3.6.2 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the p parameter.
Mikejolley Download Monitor 1.0.4
Mikejolley Download Monitor 1.0.3
Mikejolley Download Monitor 1.0.2
Mikejolley Download Monitor 1.0.1
Mikejolley Download Monitor 1.0.0
Mikejolley Download Monitor
Mikejolley Download Monitor 1.0.5
5.1
CVSSv2
CVE-2013-5962
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin prior to 3.3.4 rev40279 for WordPress allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct...
Envato Complete Gallery Manager Plugin 3.3.2
Envato Complete Gallery Manager Plugin 3.3.1
Envato Complete Gallery Manager Plugin 3.2.2
Envato Complete Gallery Manager Plugin 3.2.1
Envato Complete Gallery Manager Plugin 2.0.2
Envato Complete Gallery Manager Plugin 2.0.1
Envato Complete Gallery Manager Plugin 3.2.6
Envato Complete Gallery Manager Plugin 3.2.5
Envato Complete Gallery Manager Plugin 3.1.0
Envato Complete Gallery Manager Plugin 3.0.1
Envato Complete Gallery Manager Plugin 1.0.1
Envato Complete Gallery Manager Plugin 1.0.0
Envato Complete Gallery Manager Plugin 3.3.0
Envato Complete Gallery Manager Plugin 3.2.8
Envato Complete Gallery Manager Plugin 3.2.7
Envato Complete Gallery Manager Plugin 3.2.0
Envato Complete Gallery Manager Plugin 3.1.1
Envato Complete Gallery Manager Plugin 2.0.0
Envato Complete Gallery Manager Plugin 1.0.2
Envato Complete Gallery Manager Plugin
Envato Complete Gallery Manager Plugin 3.2.4
Envato Complete Gallery Manager Plugin 3.2.3
1 EDB exploit
4.3
CVSSv2
CVE-2013-5098
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin prior to 3.3.6.2 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.
Mikejolley Download Monitor 1.0.3
Mikejolley Download Monitor 1.0.2
Mikejolley Download Monitor 1.0.5
Mikejolley Download Monitor 1.0.4
Mikejolley Download Monitor 1.0.0
Mikejolley Download Monitor
Mikejolley Download Monitor 1.0.1
NA
CVE-2015-10093
A vulnerability was found in Mark User as Spammer Plugin 1.0.0/1.0.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function user_row_actions of the file plugin/plugin.php. The manipulation of the argument url leads to cross site scriptin...
Mark User As Spammer Project Mark User As Spammer 1.0.0
Mark User As Spammer Project Mark User As Spammer 1.0.1
6.8
CVSSv2
CVE-2014-3882
Cross-site request forgery (CSRF) vulnerability in the Login rebuilder plugin prior to 1.2.0 for WordPress allows remote malicious users to hijack the authentication of arbitrary users.
12net Login Rebuilder
12net Login Rebuilder 1.1.2
12net Login Rebuilder 1.1.0
12net Login Rebuilder 1.0.2
12net Login Rebuilder 1.0.1
12net Login Rebuilder 1.0.0
12net Login Rebuilder 1.1.1
12net Login Rebuilder 1.0.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »