Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xcloner HIGH 8.8
CVE-2020-35948EPSS 25%

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify a…

Fix: 4.2.13+
Fix from $1,950 2021-01-01
Xcloner HIGH 8.8
CVE-2020-35950

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).

Fix: 4.2.153+
Fix from $1,950 2021-01-01
Xcloner MEDIUM 6.5
CVE-2020-13424

The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.

Fix: 3.5.4+
Fix from $1,600 2020-05-23
Xcloner MEDIUM 6.5
CVE-2015-4338

Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the…

No fix yet
Fix from $1,600 2015-06-17
Xcloner MEDIUM 6.5
CVE-2015-4336

cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing …

No fix yet
Fix from $1,600 2015-06-17
Xcloner MEDIUM 5.0
CVE-2014-8605EPSS 7%

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient…

No fix yet
Fix from $1,600 2015-06-10
Xcloner MEDIUM 5.0
CVE-2014-8604EPSS 7%

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which …

No fix yet
Fix from $1,600 2015-06-10
Xcloner MEDIUM 6.5
CVE-2014-8603EPSS 6%

cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell…

No fix yet
Fix from $1,600 2015-06-10
Xcloner HIGH 7.6
CVE-2014-2579EPSS 6%

Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication …

Fix: after 3.5
Fix from $1,950 2014-04-25
Xcloner HIGH 7.1
CVE-2014-2996EPSS 10%

XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary co…

Fix: after 3.5
Fix from $1,950 2014-04-25
Xcloner MEDIUM 6.8
CVE-2014-2340

Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication…

Fix: after 3.1.0
Fix from $1,600 2014-04-03