Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Donations Made Easy Smart Donations HIGH 8.8
CVE-2023-38475

Missing Authorization vulnerability in RedNao Donations Made Easy – Smart Donations allows Exploiting Incorrectly Configured Access Control Security …

Fix: after 4.0.12
Fix from $1,950 2024-12-13
Smart Forms HIGH 8.8
CVE-2023-49856

Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

Fix: 2.6.85+
Fix from $1,950 2024-12-09
Smart Forms MEDIUM 5.9
CVE-2024-1905

The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow high privilege users such as adm…

Fix: 2.6.96+
Fix from $1,600 2024-04-29
Smart Forms MEDIUM 6.5
CVE-2024-1307

The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a s…

Fix: 2.6.94+
Fix from $1,600 2024-04-15
Smart Forms MEDIUM 5.4
CVE-2024-1306

The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform…

Fix: 2.6.94+
Fix from $1,600 2024-04-15
Woocommerce Pdf Invoice Builder HIGH 8.8
CVE-2023-51486

Cross-Site Request Forgery (CSRF) vulnerability in RedNao WooCommerce PDF Invoice Builder.This issue affects WooCommerce PDF Invoice Builder: from n/…

Fix: 1.2.102+
Fix from $1,950 2024-03-16
Smart Forms MEDIUM 6.1
CVE-2023-7203

The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as sub…

Fix: 2.6.87+
Fix from $1,600 2024-02-27
Donations Made Easy Smart Donations HIGH 8.8
CVE-2023-47551

Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations.This issue affects Donations Made Easy – Smart Donati…

Fix: after 4.0.12
Fix from $1,950 2023-11-18
Donations Made Easy Smart Donations MEDIUM 6.1
CVE-2023-47550

Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations allows Stored XSS.This issue affects Donations Made E…

Fix: after 4.0.12
Fix from $1,600 2023-11-14
Donations Made Easy Smart Donations CRITICAL 9.8
CVE-2023-40207

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations al…

Fix: after 4.0.12
Fix from $2,300 2023-11-06
Woocommerce Pdf Invoice Builder MEDIUM 6.1
CVE-2023-46076

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin …

Fix: after 1.2.102
Fix from $1,600 2023-10-26
Smart Donations MEDIUM 6.1
CVE-2023-40664

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao Donations Made Easy – Smart Donations plugin <= 4.0.12 versions.

Fix: after 4.0.12
Fix from $1,600 2023-09-27
Woocommerce Pdf Invoice Builder HIGH 8.8
CVE-2023-3677

The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in versions up to, and including, 1.…

Fix: after 1.2.89
Fix from $1,950 2023-08-31
Smart Donations MEDIUM 6.1
CVE-2023-32603

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao Donations Made Easy – Smart Donations plugin <= 4.0.12 versions.

Fix: after 4.0.12
Fix from $1,600 2023-08-25
Smart Forms MEDIUM 6.5
CVE-2022-0163

The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authentic…

Fix: 2.6.71+
Fix from $1,600 2022-03-07
Smart Forms HIGH 8.8
CVE-2019-5924

Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrat…

Fix: after 2.6.15
Fix from $1,950 2019-03-12