Vulnerabilities (CVE)

Filtered by vendor Reputeinfosystems Subscribe
Total 27 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0867 1 Reputeinfosystems 1 Pricing Table 2024-11-21 7.5 HIGH 9.8 CRITICAL
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users
CVE-2022-0739 1 Reputeinfosystems 1 Bookingpress 2024-11-21 7.5 HIGH 9.8 CRITICAL
The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection
CVE-2021-24718 1 Reputeinfosystems 1 Contact Form\, Survey \& Popup Form Plugin For Wordpress - Arforms Form Builder 2024-11-21 3.5 LOW 4.8 MEDIUM
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2019-16902 1 Reputeinfosystems 1 Arforms 2024-11-21 6.4 MEDIUM 7.5 HIGH
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.
CVE-2019-14679 1 Reputeinfosystems 1 Arprice Lite 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.
CVE-2018-15818 1 Reputeinfosystems 1 Repute Arforms 2024-11-21 6.4 MEDIUM 7.5 HIGH
An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web server privileges by sending a malicious request to admin-ajax.php.
CVE-2024-10540 1 Reputeinfosystems 1 Bookingpress 2024-11-04 N/A 6.5 MEDIUM
The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL Injection via the 'service' parameter of the bookingpress_form shortcode in all versions up to, and including, 1.1.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.