Mycred

Mycred

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 08.11.2024 10:15:03
  • Zuletzt bearbeitet 13.11.2024 20:31:08

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...

  • EPSS 0.22%
  • Veröffentlicht 25.09.2024 06:15:05
  • Zuletzt bearbeitet 02.10.2024 18:36:04

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to unauthorized modification of data...

  • EPSS 0.56%
  • Veröffentlicht 19.08.2024 20:15:08
  • Zuletzt bearbeitet 20.08.2024 15:44:20

Deserialization of Untrusted Data vulnerability in myCred allows Object Injection.This issue affects myCred: from n/a through 2.7.2.

  • EPSS 0.16%
  • Veröffentlicht 18.08.2024 13:15:03
  • Zuletzt bearbeitet 19.08.2024 12:59:59

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in myCred allows Stored XSS.This issue affects myCred: from n/a through 2.7.2.

  • EPSS 0.09%
  • Veröffentlicht 24.04.2024 11:15:47
  • Zuletzt bearbeitet 21.11.2024 09:15:32

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS.This issue affects myCred: from n/a through 2.6.3.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 24.01.2022 08:15:09
  • Zuletzt bearbeitet 21.11.2024 05:54:11

The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue

Exploit
  • EPSS 0.42%
  • Veröffentlicht 29.11.2021 09:15:07
  • Zuletzt bearbeitet 21.11.2024 03:22:26

The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting