June 6, 2023WordPress WPtouch Pro 4 Backup Disclosure

WordPress WPtouch Pro version 4 appears to leave backups in a world accessible directory under the document root.

June 5, 2023Enrollment System Project 1.0 Authentication Bypass / SQL Injection

Enrollment System Project version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

June 5, 2023Total CMS 1.7.4 Cross Site Scripting

Total CMS version 1.7.4 suffers from a cross site scripting vulnerability.

June 5, 2023Barebones CMS 2.0.2 Cross Site Scripting

Barebones CMS version 2.0.2 suffers from a persistent cross site scripting vulnerability.

June 5, 2023File Manager Advanced Shortcode 2.3.2 Remote Code Execution

File Manager Advanced Shortcode version 2.3.2 suffers from a remote code execution vulnerability.

June 5, 2023WordPress Circle Progress 1.0 Cross Site Scripting

WordPress Circle Progress plugin version 1.0 suffers from a persistent cross site scripting vulnerability.

June 5, 2023FC Red Bull Salzburg App 5.1.9-R Improper Authorization

FC Red Bull Salzburg App versions 5.1.9-R and below suffer from an improper authorization vulnerability.

June 5, 2023MotoCMS 3.4.3 SQL Injection

MotoCMS version 3.4.3 suffers from a remote SQL injection vulnerability.

June 5, 2023Advance Charity Management 1.0 Insecure Settings

Advance Charity Management version 1.0 fails to set the secure flag on a session identifier.

June 2, 2023Total CMS 1.7.4 Shell Upload

Total CMS version 1.7.4 suffers from a remote shell upload vulnerability.

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow