| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. |
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. |
| Unauthenticated Local File Inclusion in Resido <= 1.5 versions. |
| Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. |
| Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. |
| Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. |
| A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack. |
| The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved ranges through the private-ip library, and createPageSaveRequest applies the same check, so the omission is specific to this resolver. An authenticated user can direct the server to request arbitrary internal endpoints. The response is parsed as a feed or as HTML and the resolver returns the resulting url, title, description and type fields, so disclosure is limited to feed-shaped metadata and to link elements advertising RSS or Atom feeds; requests that do not parse still distinguish reachable ports from unreachable ones through the resulting error. |
| The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues axios.request with that url, the method and Content-Type recorded on the webhook, and a JSON body carrying the event data, so an authenticated user can make the server send repeated attacker-shaped requests to internal endpoints, including link-local metadata addresses. The request is blind: callWebhook discards the result and writes only a success line or the axios error to the server log, so the response is not returned through the API. |
| Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. |
| Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. |
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. |
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. |
| Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. |
| Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. |