Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2021-24622

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2014-10390

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
0
Attacker Value
Unknown

CVE-2014-10388

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
0
Attacker Value
Unknown

CVE-2014-10391

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
0
Attacker Value
Unknown

CVE-2016-10930

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
0
Attacker Value
Unknown

CVE-2014-10389

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
0
Attacker Value
Unknown

CVE-2014-10387

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
0
Attacker Value
Unknown

CVE-2019-15331

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
0
Attacker Value
Unknown

CVE-2019-7299

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includes/ajax/submit_ticket.php.
0
Attacker Value
Unknown

CVE-2018-1000131

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.
0