Show filters
82 Total Results
Displaying 41-50 of 82
Sort by:
Attacker Value
Unknown
CVE-2021-24340
Disclosure Date: June 07, 2021 (last updated February 22, 2025)
The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.
0
Attacker Value
Unknown
CVE-2021-24193
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
0
Attacker Value
Unknown
CVE-2021-21631
Disclosure Date: March 30, 2021 (last updated February 22, 2025)
Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages.
0
Attacker Value
Unknown
CVE-2020-28917
Disclosure Date: November 18, 2020 (last updated February 22, 2025)
An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext passwords if ext:felogin is installed) may be saved.
0
Attacker Value
Unknown
CVE-2020-2291
Disclosure Date: October 08, 2020 (last updated February 22, 2025)
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2019-15831
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
0
Attacker Value
Unknown
CVE-2019-15832
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
0
Attacker Value
Unknown
CVE-2019-15537
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
0
Attacker Value
Unknown
CVE-2017-18515
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
0
Attacker Value
Unknown
CVE-2019-13275
Disclosure Date: July 04, 2019 (last updated November 27, 2024)
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
0