Skip to main content

Vendor archive

atlasgondal CVEs

Beta · best-effort

7 CVEs tagged to vendor atlasgondal0 Critical, 0 High, 5 Medium, 2 Low, 0 Unrated.

CVE-2023-51510

Published Mar 16, 2024

Cross-Site Request Forgery (CSRF) vulnerability in Atlas Gondal Export Media URLs.This issue affects Export Media URLs: from n/a through 1.0.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3118

Published Jul 10, 2023

The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in the page, leading to a Reflected Cross-Site Scripting which…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-2638

Published Aug 29, 2022

The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high priv…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29452

Published Jun 15, 2022

Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress.

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-0914

Published Apr 11, 2022

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0892

Published Apr 11, 2022

The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1