Show filters
338 Total Results
Displaying 21-30 of 338
Sort by:
Attacker Value
Unknown

CVE-2024-56053

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS allows SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.5.3.
0
Attacker Value
Unknown

CVE-2024-56052

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.2.
0
Attacker Value
Unknown

CVE-2024-56051

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS allows Code Injection.This issue affects WPLMS: from n/a before 1.9.9.5.
0
Attacker Value
Unknown

CVE-2024-56050

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.3.
0
Attacker Value
Unknown

CVE-2024-56049

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.2.
0
Attacker Value
Unknown

CVE-2024-56048

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Missing Authorization vulnerability in VibeThemes WPLMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through 1.9.9.
0
Attacker Value
Unknown

CVE-2024-56047

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS allows SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.5.3.
0
Attacker Value
Unknown

CVE-2024-12596

Disclosure Date: December 18, 2024 (last updated December 18, 2024)
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.
Attacker Value
Unknown

CVE-2024-12127

Disclosure Date: December 17, 2024 (last updated December 18, 2024)
The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 0.0.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-54296

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Authentication Bypass Using an Alternate Path or Channel vulnerability in Codexpert, Inc CoSchool LMS allows Authentication Bypass.This issue affects CoSchool LMS: from n/a through 1.2.
0