CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow and panic.
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.
The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens.
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
