Filtered by vendor Metagauss
Subscriptions
Total
48 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-36345 | 1 Metagauss | 1 Download Plugin | 2024-08-03 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions. | ||||
CVE-2022-3578 | 1 Metagauss | 1 Profilegrid | 2024-08-03 | 6.1 Medium |
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | ||||
CVE-2022-0420 | 1 Metagauss | 1 Registrationmagic | 2024-08-02 | 7.2 High |
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks | ||||
CVE-2022-0232 | 1 Metagauss | 1 Leadmagic | 2024-08-02 | 4.8 Medium |
The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.2.7. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. | ||||
CVE-2022-0233 | 1 Metagauss | 1 Profilegrid | 2024-08-02 | 6.4 Medium |
The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7. | ||||
CVE-2023-52117 | 1 Metagauss | 1 Profilegrid | 2024-08-02 | 4.3 Medium |
Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6. | ||||
CVE-2023-51509 | 1 Metagauss | 1 Registrationmagic | 2024-08-02 | 7.1 High |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Reflected XSS.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.1. | ||||
CVE-2023-50846 | 1 Metagauss | 1 Registrationmagic | 2024-08-02 | 7.6 High |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.5. | ||||
CVE-2023-47645 | 1 Metagauss | 1 Registrationmagic | 2024-08-02 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Cross Site Request Forgery.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.2.6. | ||||
CVE-2023-35884 | 1 Metagauss | 1 Eventprime | 2024-08-02 | 7.1 High |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions. | ||||
CVE-2023-33326 | 1 Metagauss | 1 Eventprime | 2024-08-02 | 7.1 High |
Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions. | ||||
CVE-2023-25991 | 1 Metagauss | 1 Registrationmagic | 2024-08-02 | 5.4 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions. | ||||
CVE-2023-6447 | 1 Metagauss | 1 Eventprime | 2024-08-02 | 5.3 Medium |
The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name. | ||||
CVE-2023-5519 | 1 Metagauss | 1 Eventprime | 2024-08-02 | 4.3 Medium |
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. | ||||
CVE-2023-5238 | 1 Metagauss | 1 Eventprime | 2024-08-02 | 6.1 Medium |
The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website. | ||||
CVE-2023-4252 | 1 Metagauss | 1 Eventprime | 2024-08-02 | 5.3 Medium |
The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment. | ||||
CVE-2023-4251 | 1 Metagauss | 1 Eventprime | 2024-08-02 | 4.3 Medium |
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. | ||||
CVE-2023-4250 | 1 Metagauss | 1 Eventprime | 2024-08-02 | 6.1 Medium |
The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | ||||
CVE-2023-3713 | 1 Metagauss | 1 Profilegrid | 2024-08-02 | 8.8 High |
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily. This can be used by attackers to achieve privilege escalation. | ||||
CVE-2023-3714 | 1 Metagauss | 1 Profilegrid | 2024-08-02 | 7.5 High |
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3. |