Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
ajax search vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2012-5853
SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a...
Ajax Search Project Ajax Search
7.5
CVE-2022-38456
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions....
Ajax Search Project Ajax Search
5.3
CVE-2022-2535
The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink...
Searchwp Searchwp Live Ajax Search
7.5
CVSSv3
CVE-2020-12070
The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-search.php....
Advanced-woo-search Advanced Woo Search
9.8
CVE-2022-4297
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection...
Netflixtech Wp Autocomplete Search
1 Github repository available
4.3
CVSSv3
CVE-2019-16251
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes....
Yithemes Yith Woocommerce Wishlist
Yithemes Yith Woocommerce Compare
Yithemes Yith Woocommerce Quick View
Yithemes Yith Woocommerce Zoom Magnifier
Yithemes Yith Woocommerce Ajax Search
Yithemes Yith Woocommerce Badge Management
Yithemes Yith Woocommerce Brands Add-on
Yithemes Yith Woocommerce Request A Quote
Yithemes Yith Woocommerce Social Login
Yithemes Yith Woocommerce Order Tracking
Yithemes Yith Woocommerce Pdf Invoice And Shipping List
Yithemes Yith Pre-order For Woocommerce
Yithemes Yith Woocommerce Advanced Reviews
Yithemes Yith Woocommerce Product Add-ons
Yithemes Yith Woocommerce Gift Cards
Yithemes Yith Woocommerce Subscription
Yithemes Yith Woocommerce Affiliates
Yithemes Yith Woocommerce Cart Messages
Yithemes Yith Woocommerce Product Bundles
Yithemes Yith Woocommerce Frequently Bought Together
Yithemes Yith Woocommerce Multi-step Checkout
Yithemes Yith Color And Label Variations For Woocommerce
Yithemes Yith Custom Thank You Page For Woocommerce
Yithemes Yith Product Size Charts For Woocommerce
Yithemes Yith Woocommerce Added To Cart Popup
Yithemes Yith Woocommerce Bulk Product Editing
Yithemes Yith Woocommerce Stripe
Yithemes Yith Woocommerce Waiting List
Yithemes Yith Woocommerce Points And Rewards
Yithemes Yith Advanced Refund System For Woocommerce
Yithemes Yith Woocommerce Authorize.net Payment Gateway
Yithemes Yith Woocommerce Best Sellers
Yithemes Yith Woocommerce Mailchimp
Yithemes Yith Woocommerce Multi Vendor
Yithemes Yith Woocommerce Questions And Answers
Yithemes Yith Woocommerce Recover Abandoned Cart
Yithemes Yith Paypal Express Checkout For Woocommerce
Yithemes Yith Desktop Notifications For Woocommerce
NA
CVE-2012-5164
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the term parameter to (1) autocomplete.php, (2) search/ajax/autosuggest.php, (3) livesuggest.php, or (4) save.php in...
Fork-cms Fork Cms 2.6.2
Fork-cms Fork Cms 2.6.3
Fork-cms Fork Cms 2.3.1
Fork-cms Fork Cms 2.0.1
Fork-cms Fork Cms 2.6.12
Fork-cms Fork Cms 3.1.0
Fork-cms Fork Cms 2.6.4
Fork-cms Fork Cms 2.6.7
Fork-cms Fork Cms 3.1.6
Fork-cms Fork Cms 3.2.1
Fork-cms Fork Cms 2.4.0
Fork-cms Fork Cms 2.4.1
Fork-cms Fork Cms 2.0.2
Fork-cms Fork Cms 3.1.2
Fork-cms Fork Cms 3.0.0
Fork-cms Fork Cms 2.6.9
Fork-cms Fork Cms 2.6.6
Fork-cms Fork Cms 3.2.5
Fork-cms Fork Cms 3.2.4
Fork-cms Fork Cms 3.2.2
Fork-cms Fork Cms 3.1.9
Fork-cms Fork Cms 2.5.1
Fork-cms Fork Cms 2.5.2
Fork-cms Fork Cms 2.1.0
Fork-cms Fork Cms 3.1.1
Fork-cms Fork Cms 3.1.4
Fork-cms Fork Cms 2.6.8
Fork-cms Fork Cms 2.6.11
Fork-cms Fork Cms 3.2.3
Fork-cms Fork Cms 3.1.7
Fork-cms Fork Cms 3.2.0
Fork-cms Fork Cms
Fork-cms Fork Cms 2.6.1
Fork-cms Fork Cms 2.2.0
Fork-cms Fork Cms 2.3.0
Fork-cms Fork Cms 3.1.3
Fork-cms Fork Cms 2.6.13
Fork-cms Fork Cms 2.6.10
Fork-cms Fork Cms 2.6.5
Fork-cms Fork Cms 3.1.8
Fork-cms Fork Cms 3.1.5
Fork-cms Fork Cms 2.6.0
9.8
CVSSv3
CVE-2020-8519
SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql...
Phpzag Phpzag -
NA
CVE-2015-6516
SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitrary SQL commands via the search parameter to ajax/ajax_search.php....
Cygnux Syspass
1 EDB exploit available
NA
CVE-2014-4759
An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search...
Ibm Business Process Manager 8.5.0.0
Ibm Business Process Manager 8.5.0.1
Ibm Business Process Manager 8.5.5.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-25675
CVE-2023-21072
physical
CVE-2023-28446
encryption
CVE-2023-21076
server-side request forgery
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »