Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mstore Api HIGH 7.3
CVE-2025-3438

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up …

Fix: 4.17.5+
Fix from $1,950 2025-05-02
Mstore Api MEDIUM 5.4
CVE-2024-12042

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile pict…

Fix: 4.16.5+
Fix from $1,600 2024-12-13
Mstore Api MEDIUM 6.5
CVE-2024-11179

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in…

Fix: 4.15.8+
Fix from $1,600 2024-11-20
Mstore Api MEDIUM 6.5
CVE-2024-8269

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions u…

Fix: 4.15.4+
Fix from $1,600 2024-09-13
Mstore Api HIGH 8.8
CVE-2024-8242

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type …

Fix: 4.15.4+
Fix from $1,950 2024-09-13
Mstore Api HIGH 8.1
CVE-2024-7628

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and inc…

Fix: 4.15.3+
Fix from $1,950 2024-08-15
Mstore Api CRITICAL 9.8
CVE-2024-6328

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and…

Fix: 4.15.0+
Fix from $2,300 2024-07-12
Mstore Api HIGH 8.8
CVE-2023-50878

Cross-Site Request Forgery (CSRF) vulnerability in InspireUI MStore API.This issue affects MStore API: from n/a through 4.10.1.

Fix: after 4.10.1
Fix from $1,950 2023-12-29
Mstore Api CRITICAL 9.8
CVE-2023-45055

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This …

Fix: 4.0.7+
Fix from $2,300 2023-11-06
Mstore Api CRITICAL 9.8
CVE-2023-3277

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 du…

Fix: after 4.10.7
Fix from $2,300 2023-11-03
Mstore Api CRITICAL 9.8
CVE-2023-3076

The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale …

Fix: 3.9.9+
Fix from $2,300 2023-07-10
Mstore Api CRITICAL 9.8
CVE-2023-3077EPSS 6%

The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL inje…

Fix: 3.9.8+
Fix from $2,300 2023-07-10
Mstore Api CRITICAL 9.8
CVE-2023-3197

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0…

Fix: after 4.0.1
Fix from $2,300 2023-06-24
Mstore Api HIGH 7.5
CVE-2022-47614

Unauth. SQL Injection (SQLi) vulnerability in InspireUI MStore API plugin <= 3.9.7 versions.

Fix: after 3.9.7
Fix from $1,950 2023-06-23
Mstore Api CRITICAL 9.8
CVE-2020-36713

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted acces…

Fix: after 2.1.5
Fix from $2,300 2023-06-07
Mstore Api CRITICAL 9.8
CVE-2023-2732EPSS 68%

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verif…

Fix: after 3.9.2
Fix from $2,300 2023-05-25
Mstore Api CRITICAL 9.8
CVE-2023-2733

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verif…

Fix: after 3.9.0
Fix from $2,300 2023-05-25
Mstore Api CRITICAL 9.8
CVE-2023-2734

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verif…

Fix: after 3.9.1
Fix from $2,300 2023-05-25
Mstore Api CRITICAL 9.8
CVE-2021-24148

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unaut…

Fix: 3.2.0+
Fix from $2,300 2021-03-18