Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Supportcandy HIGH 8.8
CVE-2023-2719

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it …

Fix: 3.1.7+
Fix from $1,950 2023-06-19
Supportcandy HIGH 7.2
CVE-2023-2805

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function…

Fix: 3.1.7+
Fix from $1,950 2023-06-19
Supportcandy CRITICAL 9.8
CVE-2023-1730EPSS 41%

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthe…

Fix: 3.1.5+
Fix from $2,300 2023-05-02
Supportcandy HIGH 8.8
CVE-2021-24879

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some…

Fix: 2.2.7+
Fix from $1,950 2022-02-07
Supportcandy MEDIUM 6.5
CVE-2021-24843

The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged…

Fix: 2.2.7+
Fix from $1,600 2022-02-07
Supportcandy MEDIUM 6.1
CVE-2021-24878

The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create…

Fix: 2.2.7+
Fix from $1,600 2022-02-07
Supportcandy MEDIUM 5.4
CVE-2021-24880

The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role …

Fix: 2.2.7+
Fix from $1,600 2022-02-07
Supportcandy HIGH 7.5
CVE-2021-24839

The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthe…

Fix: 2.2.5+
Fix from $1,950 2022-02-07
Supportcandy CRITICAL 9.8
CVE-2019-11223EPSS 9%

An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by…

Fix: after 2.0.0
Fix from $2,300 2019-04-18