Skip to main content

Vendor/product archive

bravenewcode / wptouch CVEs

Beta · best-effort

4 CVEs tagged to bravenewcode / wptouch0 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-3417

Published Jan 9, 2023

The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PHP object injections issues when an user import (intentional…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3416

Published Jan 9, 2023

The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server ev…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4779

Published Apr 7, 2011

Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote attackers to inject arbitrary web scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1