Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
donations project donations vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2019-15772
The nd-donations plugin prior to 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
Donations Project Donations
9.8
CVSSv3
CVE-2022-0782
The Donations WordPress plugin up to and including 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an...
Donations Project Donations
5.4
CVSSv3
CVE-2022-29433
Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress.
Donations Project Donations
6.5
CVSSv3
CVE-2022-1610
The Seamless Donations WordPress plugin prior to 5.1.9 does not have CSRF check in place when updating its settings, which could allow malicious users to make a logged in admin change them via a CSRF attack
Seamless Donations Project Seamless Donations
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
denial of service
CVE-2024-27371
CVE-2024-20405
CVE-2024-31627
CVE-2024-31625
race condition
CVE-2024-4358
cross-site scripting
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started