Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
arvandy vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2023-2624
The KiviCare WordPress plugin prior to 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator
Iqonic Kivicare
NA
CVE-2023-48287
WordPress TextMe SMS plugin versions 1.9.0 and below suffer from a cross site request forgery vulnerability.
NA
CVE-2023-47871
WordPress Contact Form to Any API plugin versions 1.1.6 and below suffer from a cross site request forgery vulnerability.
6.1
CVSSv3
CVE-2023-37988
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.
Creative-solutions Contact Form Generator
1 Github repository
9.1
CVSSv3
CVE-2023-49161
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Guelben Bravo Translate.This issue affects Bravo Translate: from n/a up to and including 1.2.
Guelbetech Bravo Translate
7.2
CVSSv3
CVE-2023-2744
The ERP WordPress plugin prior to 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Wedevs Wp Erp
1 Github repository
7.2
CVSSv3
CVE-2023-32741
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a up to and including 1.1.2.
Itpathsolutions Contact Form To Any Api
8.8
CVSSv3
CVE-2023-24788
NotrinosERP v0.7 exists to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php.
Notrinos Notrinoserp 0.7
NA
CVE-2023-24787
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-24685. Reason: This record is a duplicate of CVE-2023-24685. Notes: All CVE users should reference CVE-2023-24685 instead of this record. All references and descriptions in this record have been removed to prevent ...
8.8
CVSSv3
CVE-2023-29842
ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.
Churchcrm Churchcrm 4.5.4
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3581
reflected XSS
CVE-2024-26925
CVE-2024-27956
LFI
CVE-2024-3607
CVE-2024-3107
CVE-2024-3295
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started