CVE-2024-10187
- EPSS 0.23%
- Veröffentlicht 08.11.2024 10:15:03
- Zuletzt bearbeitet 13.11.2024 20:31:08
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2024-8658
- EPSS 0.22%
- Veröffentlicht 25.09.2024 06:15:05
- Zuletzt bearbeitet 02.10.2024 18:36:04
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-43354
- EPSS 0.56%
- Veröffentlicht 19.08.2024 20:15:08
- Zuletzt bearbeitet 20.08.2024 15:44:20
Deserialization of Untrusted Data vulnerability in myCred allows Object Injection.This issue affects myCred: from n/a through 2.7.2.
CVE-2024-43353
- EPSS 0.16%
- Veröffentlicht 18.08.2024 13:15:03
- Zuletzt bearbeitet 19.08.2024 12:59:59
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in myCred allows Stored XSS.This issue affects myCred: from n/a through 2.7.2.
CVE-2024-32711
- EPSS 0.09%
- Veröffentlicht 24.04.2024 11:15:47
- Zuletzt bearbeitet 21.11.2024 09:15:32
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS.This issue affects myCred: from n/a through 2.6.3.
CVE-2021-25015
- EPSS 0.21%
- Veröffentlicht 24.01.2022 08:15:09
- Zuletzt bearbeitet 21.11.2024 05:54:11
The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue
CVE-2017-20008
- EPSS 0.42%
- Veröffentlicht 29.11.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 03:22:26
The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting