Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Loginizer HIGH 8.1
CVE-2024-10097

The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This …

Fix: 1.9.3+
Fix from $1,950 2024-11-05
Loginizer MEDIUM 6.1
CVE-2023-2296

The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scri…

Fix: 1.7.9+
Fix from $1,600 2023-05-30
Loginizer HIGH 8.8
CVE-2022-45079

Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.

Fix: 1.7.6+
Fix from $1,950 2023-05-22
Loginizer MEDIUM 6.1
CVE-2022-45084

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.

Fix: 1.7.6+
Fix from $1,600 2023-04-24
Loginizer CRITICAL 9.8
CVE-2020-27615EPSS 52%

The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.

Fix: 1.6.4+
Fix from $2,300 2020-10-21
Loginizer MEDIUM 6.1
CVE-2018-11366

init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandle…

Patch available
Fix from $1,600 2018-05-22
Loginizer CRITICAL 9.8
CVE-2017-12650

SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.

Fix: after 1.3.5
Fix from $2,300 2017-08-07
Loginizer HIGH 8.8
CVE-2017-12651

Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress beca…

Fix: after 1.3.5
Fix from $1,950 2017-08-07