Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

School Management System HIGH 8.8
CVE-2024-9658

The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and…

Fix: after 93.0.0
Fix from $1,950 2025-03-07
School Management System MEDIUM 5.3
CVE-2024-12610

The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '…

Fix: after 93.0.0
Fix from $1,600 2025-03-07
School Management System MEDIUM 5.3
CVE-2024-12611

The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all vers…

Fix: after 93.0.0
Fix from $1,600 2025-03-07
School Management System MEDIUM 6.5
CVE-2024-12607

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task…

Fix: 93.0.0+
Fix from $1,600 2025-03-07
School Management System MEDIUM 6.5
CVE-2024-12609

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, …

Fix: 93.0.0+
Fix from $1,600 2025-03-07
School Management System HIGH 8.8
CVE-2024-9660

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj…

Fix: 92.0.0+
Fix from $1,950 2024-11-23
School Management System CRITICAL 9.8
CVE-2024-9659

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj…

Fix: 92.0.0+
Fix from $2,300 2024-11-23
Wphrm Human Resource Management System HIGH 8.8
CVE-2017-14848

WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.

No fix yet
Fix from $1,950 2017-10-03
Smsmaster Multipurpose Sms Gateway HIGH 8.8
CVE-2017-14842

Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.

No fix yet
Fix from $1,950 2017-09-28
School Management System HIGH 8.8
CVE-2017-14843

Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.

No fix yet
Fix from $1,950 2017-09-28
Wpgym Gym Management System HIGH 8.8
CVE-2017-14844

Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.

No fix yet
Fix from $1,950 2017-09-28
Wpchurch Church Management System HIGH 8.8
CVE-2017-14845

Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.

No fix yet
Fix from $1,950 2017-09-28
Hospital Management System HIGH 8.8
CVE-2017-14846

Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.

No fix yet
Fix from $1,950 2017-09-28
Wpams Apartment Management System HIGH 8.8
CVE-2017-14847

Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.

No fix yet
Fix from $1,950 2017-09-28
Annual Maintenance Contract Management System MEDIUM 6.5
CVE-2017-14841

Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.

No fix yet
Fix from $1,600 2017-09-28