Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2023-50374
Disclosure Date: March 28, 2024 (last updated April 02, 2024)
Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.10.
0
Attacker Value
Unknown
CVE-2023-41800
Disclosure Date: October 02, 2023 (last updated October 09, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in UniConsent UniConsent CMP for GDPR CPRA GPP TCF plugin <= 1.4.2 versions.
0
Attacker Value
Unknown
CVE-2023-2159
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature.
0
Attacker Value
Unknown
CVE-2020-36730
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.
0
Attacker Value
Unknown
CVE-2022-0188
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
0
Attacker Value
Unknown
CVE-2018-9240
Disclosure Date: April 03, 2018 (last updated November 26, 2024)
ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends a long chat message, a crash and denial of service could occur.
0
Attacker Value
Unknown
CVE-2012-5224
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pages[template] parameter.
0
Attacker Value
Unknown
CVE-2011-5170
Disclosure Date: September 15, 2012 (last updated October 05, 2023)
Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist.
0
Attacker Value
Unknown
CVE-2009-2403
Disclosure Date: July 09, 2009 (last updated February 15, 2024)
Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a .m3u playlist file.
0
Attacker Value
Unknown
CVE-2008-0959
Disclosure Date: May 29, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow remote attackers to execute arbitrary code via unspecified vectors.
0