
CVE-2023-40852
https://notcve.org/view.php?id=CVE-2023-40852
16 Oct 2023 — SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page. Vulnerabilidad de inyección SQL en Phpgurukul User Registration & Login y User Management System con el panel de administración 3.0 permite a los atacantes obtener información confidencial a través de una cadena manipulada en el campo de nombre de usuario administrador... • https://www.exploit-db.com/exploits/51695 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-27225
https://notcve.org/view.php?id=CVE-2023-27225
06 Jul 2023 — A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field. • https://medium.com/%40ridheshgohil1092/my-first-cve-2023-27225-f232650f6cde • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-34648
https://notcve.org/view.php?id=CVE-2023-34648
29 Jun 2023 — A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php. • https://github.com/ckalnarayan/Common-Vulnerabilities-and-Exposures/blob/main/CVE-2023-34648 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-33591
https://notcve.org/view.php?id=CVE-2023-33591
21 Jun 2023 — User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php. • https://github.com/DARSHANAGUPTA10/CVE/blob/main/CVE%202023-33591 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-29429 – WordPress User Registration plugin <= 2.3.2.1 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2023-29429
06 Apr 2023 — Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 2.3.2.1. The User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_test_email function in versions up to, and including, 2.3.2.1. This makes it possible for unauthenticated attackers to send a test email. • https://patchstack.com/database/wordpress/plugin/user-registration/vulnerability/wordpress-user-registration-plugin-2-3-2-1-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •

CVE-2023-27459 – WordPress User Registration plugin <= 2.3.2.1 - Authenticated PHP Object Injection vulnerability
https://notcve.org/view.php?id=CVE-2023-27459
21 Mar 2023 — Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1. Vulnerabilidad de deserialización de datos no confiables en el registro de usuarios de WPeverest. Este problema afecta el registro de usuarios: desde n/a hasta 2.3.2.1. The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.2.1 via deserialization of untrusted input in the following functions: ur_get_use... • https://patchstack.com/database/vulnerability/user-registration/wordpress-user-registration-plugin-2-3-2-1-authenticated-php-object-injection-vulnerability?_s_id=cve • CWE-502: Deserialization of Untrusted Data •

CVE-2022-43097
https://notcve.org/view.php?id=CVE-2022-43097
05 Dec 2022 — Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & login pages. Phpgurukul User Registration & User Management System v3.0 contiene múltiples vulnerabilidades de cross site scripting (XSS) almacenado a través de los parámetros firstname y lastname del formulario de registro y de páginas de inicio de sesión. • https://github.com/nibin-m/CVE-2022-43097 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-23051
https://notcve.org/view.php?id=CVE-2020-23051
22 Oct 2021 — Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields. Se ha detectado que Phpgurukul User Registration & User Management System versión v2.0, contiene múltiples vulnerabilidades de tipo cross-site scripting (XSS) almacenado por medio de los parámetros firstname y lastname de los campos de entrada registration form y login... • https://www.vulnerability-lab.com/get_content.php?id=2216 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-26766
https://notcve.org/view.php?id=CVE-2020-26766
26 Dec 2020 — A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1. Se presenta una vulnerabilidad de tipo Cross Site Request Forgery (CSRF) en la página loginsystem en PHPGurukul User Registration & Login and User Management System With Admin Panel versión 2.1 • https://www.exploit-db.com/exploits/49180 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2020-24723
https://notcve.org/view.php?id=CVE-2020-24723
18 Nov 2020 — Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1. Una vulnerabilidad de tipo Cross Site Scripting (XSS) en la página de Registro del panel de administración en PHPGurukul User Registration & Login and User Management System With admin panel versión 2.1 • https://phpgurukul.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •