Filtered by vendor Web-dorado
                        
                        Subscribe
                        
                        
                    
                    
                
                    Total
                    27 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 | 
|---|---|---|---|---|---|
| CVE-2019-11557 | 1 Web-dorado | 1 Wp Form Builder | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH | 
| The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized. | |||||
| CVE-2018-5991 | 1 Web-dorado | 1 Form Maker | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL | 
| SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798. | |||||
| CVE-2018-5981 | 1 Web-dorado | 1 Gallery Wd | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL | 
| SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter. | |||||
| CVE-2018-16164 | 1 Web-dorado | 1 Event Calendar Wd | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM | 
| Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2018-10504 | 1 Web-dorado | 1 Form Maker | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH | 
| The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. | |||||
| CVE-2018-10301 | 1 Web-dorado | 1 Wd Instagram Feed | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM | 
| Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram post. | |||||
| CVE-2018-10300 | 1 Web-dorado | 1 Wd Instagram Feed | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM | 
| Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's bio. | |||||
