Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown

CVE-2015-9310

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
0
Attacker Value
Unknown

CVE-2016-10888

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
0
Attacker Value
Unknown

CVE-2016-10887

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
0
Attacker Value
Unknown

CVE-2016-10866

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
0
Attacker Value
Unknown

CVE-2016-10867

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
Attacker Value
Unknown

CVE-2015-9293

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
0
Attacker Value
Unknown

CVE-2016-10868

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
0
Attacker Value
Unknown

CVE-2015-9294

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
0
Attacker Value
Unknown

CVE-2015-0895

Disclosure Date: March 07, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not Found) HTTP status codes.
0
Attacker Value
Unknown

CVE-2015-0894

Disclosure Date: March 07, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0