CVE-2019-15331
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
Source: CVE-2019-15331
CVE-2019-15331
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
Source: CVE-2019-15331
CVE-2017-18586
The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.
Source: CVE-2017-18586
CVE-2019-15060
The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.
Source: CVE-2019-15060
CVE-2019-12386
An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.
Source: CVE-2019-12386
CVE-2019-12385
An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.
Source: CVE-2019-12385
CVE-2018-20988
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
Source: CVE-2018-20988
CVE-2016-10930
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
Source: CVE-2016-10930
CVE-2014-10388
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
Source: CVE-2014-10388
CVE-2014-10389
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
Source: CVE-2014-10389
CVE-2014-10391
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
Source: CVE-2014-10391