Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Groundhogg MEDIUM 6.1
CVE-2024-37264

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Groundhogg Inc. Groundhogg allows Reflec…

Fix: 3.4.3+
Fix from $1,600 2024-07-22
Groundhogg HIGH 8.8
CVE-2023-34178

Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11 versions.

Fix: 2.7.11.1+
Fix from $1,950 2023-11-09
Groundhogg HIGH 7.2
CVE-2023-34179

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Inc. Groundhogg allows SQL Injection…

Fix: after 2.7.11
Fix from $1,950 2023-11-03
Groundhogg HIGH 8.0
CVE-2023-2736

The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing non…

Fix: after 2.7.9.8
Fix from $1,950 2023-05-20
Groundhogg MEDIUM 5.4
CVE-2023-2716

The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'a…

Fix: after 2.7.9.8
Fix from $1,600 2023-05-20
Groundhogg MEDIUM 5.4
CVE-2023-2735

The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gh_form' shortcode in versions up to, and including, 2.7.9.…

Fix: after 2.7.9.8
Fix from $1,600 2023-05-20
Groundhogg HIGH 7.2
CVE-2023-1425

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise …

Fix: 2.7.9.4+
Fix from $1,950 2023-04-10
Groundhogg HIGH 8.8
CVE-2019-15647

The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.

Fix: 1.3.5+
Fix from $1,950 2019-08-27