January 12, 2023Blesta 5.4.1 Insecure Settings

Blesta version 5.4.1 appears to leave a default administrative account in place post installation.

January 11, 2023WordPress Royal Elementor 1.3.59 XSS / CSRF / Insufficient Access Controls

WordPress Royal Elementor add-ons versions 1.3.59 and below suffer from cross site request forgery, insufficient access control, cross site scripting vulnerabilities.

January 11, 2023Online Food Ordering System 2.0 Cross Site Scripting

Online Food Ordering System version 2.0 suffers from a cross site scripting vulnerability.

January 11, 2023Tiki Wiki CMS Groupware 25.0 Cross Site Scripting

Tiki Wiki CMS Groupware version 25.0 suffers from a cross site scripting vulnerability.

January 11, 2023Medisense-Healthcare Solutions CRM 2.0 Cross Site Request Forgery

Medisense-Healthcare Solutions CRM version 2.0 suffers from a cross site request forgery vulnerability.

January 11, 2023ERPGo SaaS CRM 3.3 Arbitrary File Upload

ERPGo SaaS CRM version 3.3 suffers from an arbitrary file upload vulnerability.

January 11, 2023eCart Web 4.0.0 Insecure Settings

eCart Web version 4.0.0 appears to leave a default administrative account in place post installation.

January 11, 2023eCart Multi Vendor eCommerce System 1.x Insecure Settings

eCart Multi Vendor eCommerce System version 1.x appears to leave a default administrative account in place post installation.

January 11, 2023Concepts Informatics CMS 7 SQL Injection

Concepts Informatics CMS version 7 suffers from a remote SQL injection vulnerability.

January 11, 2023CMS Global-PC Technology 1.0 Insecure Settings

CMS Global-PC Technology version 1.0 appears to leave a default administrative account in place post installation.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow