Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Amelia CRITICAL 9.8
CVE-2024-22298

Missing Authorization vulnerability in TMS Amelia ameliabooking.This issue affects Amelia: from n/a through 1.0.98.

Fix: 1.0.99+
Fix from $2,300 2024-06-10
Wpdatatables MEDIUM 6.1
CVE-2024-0591

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi…

Fix: 3.4.2.5+
Fix from $1,600 2024-03-13
Amelia MEDIUM 5.4
CVE-2023-6808

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod…

Fix: after 1.0.93
Fix from $1,600 2024-02-05
Amelia MEDIUM 5.4
CVE-2023-50860

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TMS Booking for Appointments and Events Calenda…

Fix: after 1.0.85
Fix from $1,600 2023-12-28
Wpdatatables HIGH 7.2
CVE-2023-4314

The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deserializing the data. This allows ad…

Fix: 2.1.66+
Fix from $1,950 2023-09-11
Amelia MEDIUM 6.1
CVE-2023-29427

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar – Amelia plugin <= 1.0.75 versions.

Fix: after 1.0.75
Fix from $1,600 2023-06-26
Amelia MEDIUM 6.1
CVE-2023-27918

Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthen…

Fix: 1.0.76+
Fix from $1,600 2023-05-10
Wpdatatables MEDIUM 5.4
CVE-2023-23876

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TMS-Plugins wpDataTables plugin <= 2.1.49 versions.

Fix: 2.1.50+
Fix from $1,600 2023-05-03
Amelia MEDIUM 5.4
CVE-2022-0825

The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's book…

Fix: 1.0.49+
Fix from $1,600 2022-04-04
Amelia MEDIUM 5.4
CVE-2022-0837

The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid tes…

Fix: 1.0.48+
Fix from $1,600 2022-04-04
Amelia MEDIUM 5.4
CVE-2022-0720

The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's book…

Fix: 1.0.47+
Fix from $1,600 2022-03-28
Amelia HIGH 8.8
CVE-2022-0687

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backd…

Fix: 1.0.47+
Fix from $1,950 2022-03-21
Amelia MEDIUM 6.1
CVE-2022-0627

The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Re…

Fix: 1.0.47+
Fix from $1,600 2022-03-21
Wpdatatables MEDIUM 6.5
CVE-2021-24200

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based bli…

Fix: 3.4.2+
Fix from $1,600 2021-04-12
Wpdatatables HIGH 8.1
CVE-2021-24197

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that v…

Fix: 3.4.2+
Fix from $1,950 2021-04-12
Wpdatatables HIGH 8.1
CVE-2021-24198

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that v…

Fix: 3.4.2+
Fix from $1,950 2021-04-12
Wpdatatables MEDIUM 6.5
CVE-2021-24199

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based bli…

Fix: 3.4.2+
Fix from $1,600 2021-04-12
Wpdatatables Lite HIGH 7.2
CVE-2019-6012

SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL comman…

Fix: after 2.0.11
Fix from $1,950 2019-12-26
Wpdatatables Lite MEDIUM 6.1
CVE-2019-6011

Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via…

Fix: after 2.0.11
Fix from $1,600 2019-12-26