CVE-2026-24593
- EPSS 0.01%
- Veröffentlicht 23.01.2026 14:29:01
- Zuletzt bearbeitet 26.01.2026 15:03:51
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Retrieve Embedded Sensitive Data.This issue affects AWP Classifieds: from n/a thro...
CVE-2025-57928
- EPSS 0.04%
- Veröffentlicht 22.09.2025 18:25:07
- Zuletzt bearbeitet 22.09.2025 21:22:33
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Team AWP Classifieds allows Code Injection. This issue affects AWP Classifieds: from n/a through 4.3.5.
CVE-2024-31350
- EPSS 0.24%
- Veröffentlicht 09.06.2024 18:15:09
- Zuletzt bearbeitet 21.11.2024 09:13:20
Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1.
CVE-2023-41801
- EPSS 0.05%
- Veröffentlicht 06.10.2023 15:15:14
- Zuletzt bearbeitet 21.11.2024 08:21:42
Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.
CVE-2022-3254
- EPSS 87.33%
- Veröffentlicht 31.10.2022 16:15:11
- Zuletzt bearbeitet 06.05.2025 16:15:24
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active...
CVE-2014-10012
- EPSS 0.17%
- Veröffentlicht 13.01.2015 11:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
CVE-2014-10013
- EPSS 1.9%
- Veröffentlicht 13.01.2015 11:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.