Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown
CVE-2015-9310
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
0
Attacker Value
Unknown
CVE-2016-10888
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
0
Attacker Value
Unknown
CVE-2016-10887
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
0
Attacker Value
Unknown
CVE-2016-10866
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
0
Attacker Value
Unknown
CVE-2016-10867
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
0
Attacker Value
Unknown
CVE-2015-9293
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
0
Attacker Value
Unknown
CVE-2016-10868
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
0
Attacker Value
Unknown
CVE-2015-9294
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
0
Attacker Value
Unknown
CVE-2015-0895
Disclosure Date: March 07, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not Found) HTTP status codes.
0
Attacker Value
Unknown
CVE-2015-0894
Disclosure Date: March 07, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0