Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Invoice MEDIUM 6.1
CVE-2022-1617

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as es…

Fix: after 4.3.1
Fix from $1,600 2024-01-16
Wp Crm HIGH 7.8
CVE-2022-1202

The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulne…

Fix: after 1.2.1
Fix from $1,950 2022-06-13
Wp Invoice MEDIUM 6.5
CVE-2016-11011

The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.

Fix: 4.1.1+
Fix from $1,600 2019-09-20
Wp Invoice MEDIUM 5.3
CVE-2016-11006

The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.

Fix: 4.1.1+
Fix from $1,600 2019-09-20
Wp Invoice MEDIUM 5.3
CVE-2016-11007

The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.

Fix: 4.1.1+
Fix from $1,600 2019-09-20
Wp Invoice MEDIUM 5.3
CVE-2016-11008

The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.

Fix: 4.1.1+
Fix from $1,600 2019-09-20
Wp Invoice MEDIUM 5.3
CVE-2016-11009

The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.

Fix: 4.1.1+
Fix from $1,600 2019-09-20
Wp Invoice MEDIUM 5.3
CVE-2016-11010

The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.

Fix: 4.1.1+
Fix from $1,600 2019-09-20