2 results (0.005 seconds)

CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 0

24 Jan 2025 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yannick Lefebvre Bug Library allows Blind SQL Injection. This issue affects Bug Library: from n/a through 2.1.4. The Bug Library plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributo... • https://patchstack.com/database/wordpress/plugin/bug-library/vulnerability/wordpress-bug-library-plugin-2-1-4-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

09 Sep 2021 — The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter found in the ~/bug-library.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.3. El plugin Bug Library de WordPress, es vulnerable a un ataque de tipo Cross-Site Scripting Reflejado por medio del parámetro successimportcount encontrado en el archivo ~/bug-library.php que permite a atacantes inyectar scripts web arbitrario, en versiones hasta ... • https://plugins.trac.wordpress.org/browser/bug-library/trunk/bug-library.php?rev=2571533#L1358 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •