Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-1617 The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as es… Wp Invoice after 4.3.1 Fix from $1,6002024-01-16 HIGH 7.8 CVE-2022-1202 The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulne… Wp Crm after 1.2.1 Fix from $1,9502022-06-13 MEDIUM 6.5 CVE-2016-11011 The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation. Wp Invoice 4.1.1+ Fix from $1,6002019-09-20 MEDIUM 5.3 CVE-2016-11006 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes. Wp Invoice 4.1.1+ Fix from $1,6002019-09-20 MEDIUM 5.3 CVE-2016-11007 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval. Wp Invoice 4.1.1+ Fix from $1,6002019-09-20 MEDIUM 5.3 CVE-2016-11008 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates. Wp Invoice 4.1.1+ Fix from $1,6002019-09-20 MEDIUM 5.3 CVE-2016-11009 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates. Wp Invoice 4.1.1+ Fix from $1,6002019-09-20 MEDIUM 5.3 CVE-2016-11010 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates. Wp Invoice 4.1.1+ Fix from $1,6002019-09-20