CVE
SCOPERTE
Vulnerabilità pubblicamente riconosciute scoperte dal nostro team di ricerca durante attività di assessment e bug bounty responsabili.
CVE-2024-53788 – WORDPRESS PORTFOLIO BUILDER – PORTFOLIO GALLERY
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Portfoliohub WordPress Portfolio Builder – Portfolio Gallery allows Stored XSS.This issue affects WordPress Portfolio Builder – Portfolio Gallery: from n/a through 1.1.7.
CVE-2024-53783 – NI WOOCOMMERCE COST OF GOODS
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Anzia Ni WooCommerce Cost Of Goods allows SQL Injection.This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.
CVE-2024-51615 – WORDPRESS AUCTION PLUGIN
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows SQL Injection.This issue affects WordPress Auction Plugin: from n/a through 3.7.
CVE-2025-22349 – WORDPRESS AUCTION PLUGIN
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows SQL Injection.This issue affects WordPress Auction Plugin: from n/a through 3.7.
CVE-2024-54207 – WORDPRESS AUCTION PLUGIN
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows Stored XSS.This issue affects WordPress Auction Plugin: from n/a through 3.7.
CVE-2024-51815 – S2MEMBER PRO
Improper Control of Generation of Code (‘Code Injection’) vulnerability in WP Sharks s2Member Pro allows Code Injection.This issue affects s2Member Pro: from n/a through 241114.
CVE-2025-26988 – SMS ALERT ORDER NOTIFICATIONS – WOOCOMMERCE
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows SQL Injection. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.
CVE-2025-26984 – SMS ALERT ORDER NOTIFICATIONS – WOOCOMMERCE
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows Reflected XSS. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.
CVE-2025-22665 – RAPIDLOAD
Missing Authorization vulnerability in Shakeeb Sadikeen RapidLoad allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RapidLoad: from n/a through 2.4.4.
CVE-2024-50407 – NAMASTE! LMS
Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Kiboko Labs Namaste! LMS allows Reflected XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.
CVE-2024-52393 – PODLOVE PODCAST PUBLISHER
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.15.
CVE-2024-50465 – PREMIUM SEO PACK
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in WP SEO – Calin Vingan Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 1.6.001.
CVE-2024-50409 – NAMASTE! LMS
Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Kiboko Labs Namaste! LMS allows Stored XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.
CVE-2024-52427 – EVENT TICKETS WITH TICKET SCANNER
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11.
CVE-2024-52434 – POPUP BY SUPSYSTIC
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic Popup by Supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through 1.10.29.
CVE-2024-52436 – POST SMTP
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Post SMTP allows Blind SQL Injection.This issue affects Post SMTP: from n/a through 2.9.9.
CVE-2024-49691 – PRODUCT FILTER BY WBW
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Woobewoo Product Filter by WBW allows SQL Injection.This issue affects Product Filter by WBW: from n/a through 2.7.0.
CVE-2024-49244 – CSV PRODUCT IMPORT EXPORT FOR WOOCOMMERCE
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in cmssoft CSV Product Import Export for WooCommerce allows SQL Injection.This issue affects CSV Product Import Export for WooCommerce: from n/a through 1.0.0.
CVE-2024-47312 – CLASSIC EDITOR AND CLASSIC WIDGETS
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in WPGrim Classic Editor and Classic Widgets allows SQL Injection.This issue affects Classic Editor and Classic Widgets: from n/a through 1.4.1.
CVE-2024-47306 – SECURE COPY CONTENT PROTECTION AND CONTENT LOCKING
Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking allows Stored XSS.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.2.3.
CVE-2024-47350 – YITH WOOCOMMERCE AJAX SEARCH
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in YITH YITH WooCommerce Ajax Search allows SQL Injection.This issue affects YITH WooCommerce Ajax Search: from n/a through 2.8.0.
CVE-2024-48020 – BACKUP AND STAGING BY WP TIME CAPSULE
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Revmakx Backup and Staging by WP Time Capsule allows SQL Injection.
CVE-2024-47376 – SLIDESHOW GALLERY
Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Tribulant Slideshow Gallery allows Stored XSS.This issue affects Slideshow Gallery: from n/a through 1.8.3.
CVE-2024-47331 – MULTI STEP FOR CONTACT FORM
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in NinjaTeam Multi Step for Contact Form allows SQL Injection.This issue affects Multi Step for Contact Form: from n/a through 2.7.7.
CVE-2024-48042 – CONTACT FORM BY SUPSYSTIC
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic Contact Form by Supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through 1.7.28.
CVE-2023-4347 – LIBRENMS
Reflected XSS Reflected Cross-Site Scripting (XSS) vulnerability in LibreNMS 22.12.0 – Fri Dec 30 2022 10:11:51 GMT+0100 allows attackers to execute arbitrary external javascript code in the browser affected from /ports/group parameter. POC – Proof of concept PAYLOAD:http://YOURSITE/ports/group=OOOOO%3C%2Fscript%3E%3Cscript%3Ealert(document.
CVE-2023-1367 – EASYAPPOINTMENTS
Stored Html Injection easyappointments present an html injection vulnerability on the company name field on “/index.php/backend/settings” page. POC – Proof of concept login as admin go to /index.php/backend/settings Page insert the payload in Company Name field go back to the home page and see the result.
CVE-2023-1243 – ANSWER
Stored XSS answer has a feature to customize the “Site Name” during installation or in the settings page , due to a bad sanitization it allows to put arbitrary html code which allows to execute javascript code. Everytime a user enter in the website, the xss is triggered.
CVE-2023-0289 – WEBCALENDAR
Stored XSS Webcalendar has a feature to add event and display the location of it. This feature lead to stored xss everytime a user open the calendar or the event detail page.
CVE-2022-4690 – USEMEMOS
Stored XSS Usememos has a feature to upload file and display it. By uploading a crafted SVG files, the users can perform Stored XSS attack with the image direct link.
CVE-2022-4605 – FLATPRESS
RCE – Remote Code Execution flatpresshas a feature to upload file “uploader” and display from “media manager”. By uploading SVG files, the users can perform Stored XSS attack.
CVE-2022-4606 – FLATPRESS
RCE – Remote Code Execution flatpress has a feature to upload file “uploader” and display from “media manager”. By uploading a malicious PHP files, the users can perform Php Remote file Inclusion attack and gain RCE.
CVE-2022-3869 – FROXLOR
Html Injection in Login Page HTML Injection is a vulnerability in which the attacker can inject malicious html content in the login webpage. POC – Proof of concept PAYLOAD: https://demo.froxlor.org/index.php?showmessage=4&customermail=%22%3Cmarquee%3E%3Ch3%3EHTML/INJECTION/HERE% [email protected] Impact They can manipulate a trustful but vulnerable website against HTML Injection.
CVE-2022-3608 – PHPMYFAQ
Stored XSS and possible RCE/LFI phpmyfaq has a feature to restore from a backup the entire application. An attacker with admin grant can export the configuration and re-upload the same file bypassing all the backend sanitization and controls.
CVE-2022-4733 – OPENEMR
Stored XSS Openemr has a feature to customize the “User Manual Link Override” , due to a bad sanitization it allows to put javascript:// scheme which allows to execute javascript code.
CVE-2022-39262 – GLPI
GPLI – Stored XSS GPLI has a feature to customize the “Text in the login box ” , due to a bad sanitization it allows to put some html tag like “form” scheme which allows to execute javascript code. POC – Proof of concept login as user glpi/glpi (admin user) go to HOME->SETUP->GENERAL http://yoursite.com/front/config.form.
CVE-2022-3355 – INVENTREE
Inventree- Stored XSS By uploading SVG files, the users can perform Stored XSS attack. Copy the following code and save as filename.svg.