Security Vulnerabilities
- CVEs Published In September 2019
The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS.
The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS.
The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter.
The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter.
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.
The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file= XSS.
App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring.
The Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter.
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.