CVE-2024-31229
- EPSS 0.15%
- Veröffentlicht 18.04.2024 11:15:37
- Zuletzt bearbeitet 21.11.2024 09:13:05
Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.2.3.
CVE-2024-1592
- EPSS 0.06%
- Veröffentlicht 02.03.2024 07:15:46
- Zuletzt bearbeitet 01.08.2025 02:04:53
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD...
CVE-2023-6498
- EPSS 0.1%
- Veröffentlicht 04.01.2024 04:15:09
- Zuletzt bearbeitet 21.11.2024 08:43:58
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible...
CVE-2023-34030
- EPSS 0.14%
- Veröffentlicht 30.11.2023 14:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:26
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5; Complianz Premium: from n/a through 6....
CVE-2023-33333
- EPSS 0.18%
- Veröffentlicht 30.11.2023 14:15:08
- Zuletzt bearbeitet 21.11.2024 08:05:26
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n/a through 6.4.4; Complianz Premium: from n/a through 6....
CVE-2023-1069
- EPSS 0.19%
- Veröffentlicht 27.03.2023 16:15:09
- Zuletzt bearbeitet 18.02.2025 21:15:14
The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users ...
CVE-2022-3494
- EPSS 0.92%
- Veröffentlicht 07.11.2022 10:15:12
- Zuletzt bearbeitet 01.05.2025 20:15:33
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user wi...
CVE-2022-0193
- EPSS 0.21%
- Veröffentlicht 14.02.2022 12:15:16
- Zuletzt bearbeitet 21.11.2024 06:38:06
The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting