Skip to main content

Vendor archive

tychesoftwares CVEs

Beta · best-effort

24 CVEs tagged to vendor tychesoftwares2 Critical, 5 High, 17 Medium, 0 Low, 0 Unrated.

CVE-2025-2942

Published Jul 11, 2025

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56242

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Stored XSS.This i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38783

Published Nov 1, 2024

Missing Authorization vulnerability in Tyche Softwares Arconix FAQ allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Arconix FAQ: from n/a through…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38769

Published Nov 1, 2024

Missing Authorization vulnerability in Tyche Softwares Arconix Shortcodes allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Arconix Shortcodes: fr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10226

Published Oct 29, 2024

The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insuf…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9703

Published Oct 18, 2024

The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 2.1.12 due to in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2986

Published Jun 8, 2023

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryptio…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2023-23703

Published May 16, 2023

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Arconix Shortcodes plugin <= 2.1.7 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1