Wp-property-hive

Propertyhive

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.6%
  • Veröffentlicht 08.01.2025 06:15:16
  • Zuletzt bearbeitet 14.05.2025 15:42:36

The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

  • EPSS 0.38%
  • Veröffentlicht 01.11.2024 15:15:20
  • Zuletzt bearbeitet 29.01.2025 20:18:25

Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.

  • EPSS 0.34%
  • Veröffentlicht 17.09.2024 08:15:02
  • Zuletzt bearbeitet 27.09.2024 18:36:00

The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for un...

  • EPSS 0.26%
  • Veröffentlicht 08.06.2024 15:15:53
  • Zuletzt bearbeitet 21.11.2024 09:20:41

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13.

  • EPSS 0.33%
  • Veröffentlicht 06.05.2024 19:15:09
  • Zuletzt bearbeitet 28.04.2026 19:25:20

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.

  • EPSS 0.62%
  • Veröffentlicht 02.05.2024 17:15:28
  • Zuletzt bearbeitet 08.04.2026 19:21:24

The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, wit...

  • EPSS 0.38%
  • Veröffentlicht 11.04.2024 01:25:07
  • Zuletzt bearbeitet 28.04.2026 19:23:36

Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9.

  • EPSS 0.4%
  • Veröffentlicht 27.03.2024 08:15:39
  • Zuletzt bearbeitet 28.04.2026 19:23:52

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8.

  • EPSS 0.32%
  • Veröffentlicht 26.03.2024 12:15:49
  • Zuletzt bearbeitet 28.04.2026 19:23:20

Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.

  • EPSS 0.52%
  • Veröffentlicht 12.02.2024 08:15:40
  • Zuletzt bearbeitet 28.04.2026 19:23:17

Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.