Show filters
338 Total Results
Displaying 21-30 of 338
Sort by:
Attacker Value
Unknown
CVE-2024-56053
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS allows SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.5.3.
0
Attacker Value
Unknown
CVE-2024-56052
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.2.
0
Attacker Value
Unknown
CVE-2024-56051
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS allows Code Injection.This issue affects WPLMS: from n/a before 1.9.9.5.
0
Attacker Value
Unknown
CVE-2024-56050
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.3.
0
Attacker Value
Unknown
CVE-2024-56049
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.2.
0
Attacker Value
Unknown
CVE-2024-56048
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Missing Authorization vulnerability in VibeThemes WPLMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through 1.9.9.
0
Attacker Value
Unknown
CVE-2024-56047
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS allows SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.5.3.
0
Attacker Value
Unknown
CVE-2024-12596
Disclosure Date: December 18, 2024 (last updated December 18, 2024)
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.
0
Attacker Value
Unknown
CVE-2024-12127
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 0.0.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-54296
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Authentication Bypass Using an Alternate Path or Channel vulnerability in Codexpert, Inc CoSchool LMS allows Authentication Bypass.This issue affects CoSchool LMS: from n/a through 1.2.
0