Skip to main content

Vendor archive

ninjateam CVEs

Beta · best-effort

36 CVEs tagged to vendor ninjateam4 Critical, 6 High, 25 Medium, 1 Low, 0 Unrated.

CVE-2025-5236

Published May 30, 2025

The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.1 due to ins…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-26977

Published Feb 25, 2025

Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-12331

Published Dec 19, 2024

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' function in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25966

Published Dec 9, 2024

Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through 5.…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-53825

Published Dec 6, 2024

Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a t…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9669

Published Nov 28, 2024

The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. Th…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8066

Published Nov 28, 2024

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and inc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10533

Published Nov 16, 2024

The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the ajax_install_plugin() function in all versions up t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10055

Published Oct 18, 2024

The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsaio_snapchat shortcode in all versi…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49281

Published Oct 17, 2024

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget suppor…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47331

Published Oct 11, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi Step for Contact Form cf7-multi-step allows SQL Injection.Th…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6617

Published Sep 13, 2024

The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perf…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6493

Published Sep 13, 2024

The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perf…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7031

Published Aug 3, 2024

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4664

Published Jun 27, 2024

The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Script…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35166

Published May 14, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2346

Published May 2, 2024

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 vi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2345

Published May 2, 2024

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the folder name parameter in all versions up to…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2837

Published Apr 26, 2024

The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Script…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2513

Published Apr 9, 2024

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in all versions up to, and including, 3.6.2 due to insufficien…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1761

Published Mar 7, 2024

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 due to insufficient inp…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51370

Published Feb 12, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam WP Chat App allows Stored XSS.This issue affects WP Chat App: from…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0691

Published Feb 5, 2024

The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to insufficient input s…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 36 CVEsPage 1 of 2