Skip to main content

Vendor/product archive

incsub / hummingbird CVEs

Beta · best-effort

4 CVEs tagged to incsub / hummingbird1 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-43118

Published Nov 1, 2024

Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32792

Published Jun 9, 2024

Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.7.3.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1478

Published Apr 10, 2023

The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-0994

Published Apr 18, 2022

The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting a…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1