Skip to main content

Vendor archive

dev4press CVEs

Beta · best-effort

12 CVEs tagged to vendor dev4press0 Critical, 6 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-0852

Published May 15, 2025

The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated use…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0868

Published Apr 17, 2024

The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25093

Published Feb 29, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Rating System allows Stored XSS.This issue affects GD Ratin…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46821

Published Nov 6, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Security Headers allows auth. (admin+) SQL Injection.This i…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40330

Published Sep 27, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Milan Petrovic GD Security Headers plugin <= 1.6.1 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3122

Published Jul 12, 2023

The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 3.9.3 due to insufficient input sanitizati…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2015-5482

Published Aug 18, 2015

Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a ..…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5481

Published Aug 18, 2015

Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2839

Published Jan 12, 2015

SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2838

Published Jan 12, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote attackers to hijack the authentication of administrators f…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1