Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
login vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2023-0522
The Enable/Disable Auto Login when Register WordPress plugin up to and including 1.1.0 does not have CSRF check in place when updating its settings, which could allow malicious users to make a logged in admin change them via a CSRF attack
Enable\\/disable Auto Login When Register Project Enable\\/disable Auto Login When Register
5.4
CVSSv3
CVE-2024-24712
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a up to and including 1.1.30.
Heateor Social Login
7.5
CVSSv3
CVE-2023-41936
Jenkins Google Login Plugin 1.7 and previous versions uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing malicious users to use statistical methods to obtain a valid token.
Jenkins Google Login
NA
CVE-2007-4342
PHP remote file inclusion vulnerability in include.php in PHPCentral Login 1.0 allows remote malicious users to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. NOTE: a third party disputes this vulnerability because of the special nature of the SERVE...
Phpcentral Login 1.0
8.8
CVSSv3
CVE-2023-37946
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and previous versions does not invalidate the previous session on login.
Jenkins Openshift Login
6.1
CVSSv3
CVE-2023-37947
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and previous versions improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing malicious users to perform phishing attacks.
Jenkins Openshift Login
4.8
CVSSv3
CVE-2023-2223
The Login rebuilder WordPress plugin prior to 2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multis...
12net Login Rebuilder
6.1
CVSSv3
CVE-2017-18501
The social-login-bws plugin prior to 0.2 for WordPress has multiple XSS issues.
Bestwebsoft Social Login
NA
CVE-2007-1766
PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the root parameter.
Msxstudios Advanced Login
1 EDB exploit
5.4
CVSSv3
CVE-2022-4838
The Clean Login WordPress plugin prior to 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used aga...
Codection Clean Login
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »