Filtered by vendor Metagauss
Subscriptions
Total
93 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-52117 | 1 Metagauss | 1 Profilegrid | 2024-11-21 | 4.3 Medium |
Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6. | ||||
CVE-2023-51509 | 1 Metagauss | 1 Registrationmagic | 2024-11-21 | 7.1 High |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Reflected XSS.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.1. | ||||
CVE-2023-50846 | 1 Metagauss | 1 Registrationmagic | 2024-11-21 | 7.6 High |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.5. | ||||
CVE-2023-4251 | 1 Metagauss | 1 Eventprime | 2024-11-21 | 4.3 Medium |
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. | ||||
CVE-2023-4250 | 1 Metagauss | 1 Eventprime | 2024-11-21 | 6.1 Medium |
The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | ||||
CVE-2023-47645 | 1 Metagauss | 1 Registrationmagic | 2024-11-21 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Cross Site Request Forgery.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.2.6. | ||||
CVE-2023-47644 | 1 Metagauss | 1 Profilegrid | 2024-11-21 | 5.4 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.6.6. | ||||
CVE-2023-45637 | 1 Metagauss | 1 Eventprime | 2024-11-21 | 7.1 High |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions. | ||||
CVE-2023-35884 | 1 Metagauss | 1 Eventprime | 2024-11-21 | 7.1 High |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions. | ||||
CVE-2023-33326 | 1 Metagauss | 1 Eventprime | 2024-11-21 | 7.1 High |
Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions. | ||||
CVE-2023-0940 | 1 Metagauss | 1 Profilegrid | 2024-11-21 | 8.8 High |
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones. | ||||
CVE-2022-3578 | 1 Metagauss | 1 Profilegrid | 2024-11-21 | 6.1 Medium |
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | ||||
CVE-2022-38062 | 1 Metagauss | 1 Download Theme | 2024-11-21 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Theme plugin <= 1.0.9 versions. | ||||
CVE-2022-36352 | 1 Metagauss | 1 Profilegrid | 2024-11-21 | 6.3 Medium |
Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.0.3. | ||||
CVE-2022-36345 | 1 Metagauss | 1 Download Plugin | 2024-11-21 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions. | ||||
CVE-2022-0420 | 1 Metagauss | 1 Registrationmagic | 2024-11-21 | 7.2 High |
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks | ||||
CVE-2021-25059 | 1 Metagauss | 1 Download Plugin | 2024-11-21 | 4.3 Medium |
The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website. | ||||
CVE-2021-24862 | 1 Metagauss | 1 Registrationmagic | 2024-11-21 | 7.2 High |
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue | ||||
CVE-2021-24703 | 1 Metagauss | 1 Download Plugin | 2024-11-21 | 5.7 Medium |
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed. | ||||
CVE-2021-24648 | 1 Metagauss | 1 Registrationmagic | 2024-11-21 | 6.1 Medium |
The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting |