| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions. |
| Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions. |
| Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions. |
| Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. |
| Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. |
| Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. |
| Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. |
| Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions. |
| Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. |
| Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup & Restore <= 2.1.2 versions. |
| Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions. |
| Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions. |
| Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions. |
| Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions. |
| Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1. |
| Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1. |
| The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input. |
| Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1. |