Tag
#php
The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
PHPJabbers Car Park Booking System version 2.0 suffers from a cross site scripting vulnerability.
Zstore version 6.6.0 suffers from a cross site scripting vulnerability.
PHPJabbers Event Ticketing System Script version 1.0 suffers from a cross site scripting vulnerability.
PHPJabbers Travel Tours Script version 1.0 suffers from a remote SQL injection vulnerability.
PHPJabbers Travel Tours Script version 1.0 suffers from a cross site scripting vulnerability.
PHPJabbers Property Listing Script version 3.1 suffers from a remote SQL injection vulnerability.
PHPJabbers Property Listing Script version 3.1 suffers from a cross site scripting vulnerability.
The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via client-side scripts rather than server-side. This makes it possible for unauthenticated attackers to bypass any login restrictions that may prevent a brute force attack.
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure.