| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments. |
| Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. |
| Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. |
| Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. |
| Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. |
| Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. |
| Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. |
| Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. |
| Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. |
| Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. |
| Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. |
| Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. |
| Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. |
| Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. |
| Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. |