Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-29423: Countdown, Coming Soon, Maintenance – Countdown & Clock

Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.

CVE
#vulnerability#web#google#js#git#wordpress#php
CVE-2022-23802: Guru Change Log - Joomla LMS - LMS for Joomla eLearning

Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private information and components, possibility to view other users' information.

CVE-2021-36912: Andrea Pernici News Sitemap for Google

Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role.

Craft CMS 3.7.36 Password Reset Poisoning Attack

Craft CMS version 3.7.36 suffers from a password reset poisoning vulnerability. An unauthenticated attacker who knows valid email addresses or account names of Craft CMS backend users is able to manipulate the password reset functionality in a way that the registered users of the CMS receive password reset emails containing a malicious password reset link.

ChatBot Application With A Suggestion Feature 1.0 SQL Injection

ChatBot Application with a Suggestion Feature version 1.0 suffers from a remote blind SQL injection vulnerability.

CVE-2020-19212: SQL injection in group_list.php · Issue #1009 · Piwigo/Piwigo

SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.

CVE-2020-19213: SQL injection in cat_move.php · Issue #1010 · Piwigo/Piwigo

SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.

CVE-2020-19215: SQL injection in user/group permissions manager · Issue #1011 · Piwigo/Piwigo

SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.