Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2024-10097 The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This … Loginizer 1.9.3+ Fix from $1,9502024-11-05 MEDIUM 6.1 CVE-2023-2296 The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scri… Loginizer 1.7.9+ Fix from $1,6002023-05-30 HIGH 8.8 CVE-2022-45079 Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions. Loginizer 1.7.6+ Fix from $1,9502023-05-22 MEDIUM 6.1 CVE-2022-45084 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions. Loginizer 1.7.6+ Fix from $1,6002023-04-24 CRITICAL 9.8 CVE-2020-27615EPSS 52% The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip. Loginizer 1.6.4+ Fix from $2,3002020-10-21 MEDIUM 6.1 CVE-2018-11366 init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandle… Loginizer Patch available Fix from $1,6002018-05-22 CRITICAL 9.8 CVE-2017-12650 SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header. Loginizer after 1.3.5 Fix from $2,3002017-08-07 HIGH 8.8 CVE-2017-12651 Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress beca… Loginizer after 1.3.5 Fix from $1,9502017-08-07