
CVE-2023-26016 – WordPress Simple Portfolio Gallery Plugin <= 0.1 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-26016
23 Feb 2023 — Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions. The Simple Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1 via admin settings due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, and above, to inject arbitrary web scripts in pages that will execute whenever a user a... • https://patchstack.com/database/vulnerability/simple-portfolio-gallery/wordpress-simple-portfolio-gallery-plugin-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-23717 – WordPress Portfolio Slideshow Plugin <= 1.13.0 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-23717
17 Feb 2023 — Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in George Gecewicz Portfolio Slideshow plugin <= 1.13.0 versions. The Portfolio Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in page... • https://patchstack.com/database/vulnerability/portfolio-slideshow/wordpress-portfolio-slideshow-plugin-1-13-0-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-34649 – Simple Behance Portfolio <= 0.2 Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-34649
13 Aug 2021 — The Simple Behance Portfolio WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `dark` parameter in the ~/titan-framework/iframe-font-preview.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.2. El plugin Simple Behance Portfolio de WordPress, es vulnerable a un ataque de tipo Cross-Site Scripting Reflejado por medio del parámetro "dark" en el archivo ~/titan-framework/iframe-font-preview.php que permite a atacantes inyectar scripts web ... • https://plugins.trac.wordpress.org/browser/simple-behace-portfolio/trunk/titan-framework/iframe-font-preview.php#L141 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-17693
https://notcve.org/view.php?id=CVE-2017-17693
15 Dec 2017 — Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback. Techno - Portfolio Management Panel hasta la versión 2017-11-16 no comprueba la autorización para peticiones panel/portfolio.php?action=delete que eliminan el feedback. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/Techno-Portfolio-Management-Panel.md • CWE-862: Missing Authorization •

CVE-2017-17694
https://notcve.org/view.php?id=CVE-2017-17694
15 Dec 2017 — Techno - Portfolio Management Panel through 2017-11-16 allows XSS via the panel/search.php s parameter. Techno - Portfolio Management Panel hasta la versión 2017-11-16 permite XSS mediante el parámetro s en panel/search.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/Techno-Portfolio-Management-Panel.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-17695
https://notcve.org/view.php?id=CVE-2017-17695
15 Dec 2017 — Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter. Techno - Portfolio Management Panel hasta la versión 2017-11-16 permite la inyección SQL mediante el parámetro s en panel/search.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/Techno-Portfolio-Management-Panel.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2017-17696
https://notcve.org/view.php?id=CVE-2017-17696
15 Dec 2017 — Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/search.php. Techno - Portfolio Management Panel hasta la versión 2017-11-16 permite la revelación de rutas mediante un parámetro s inválido en panel/search.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/Techno-Portfolio-Management-Panel.md • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-17110 – Techno Portfolio Management Panel - 'id' SQL Injection
https://notcve.org/view.php?id=CVE-2017-17110
06 Dec 2017 — Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request. Techno Portfolio Management Panel 1.0 permite que un atacante inyecte comandos SQL mediante una petición single.php?id=. Techno Portfolio Management Panel version 1.0 suffers from a remote SQL injection vulnerability. • https://packetstorm.news/files/id/145231 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2015-6523 – Portfolio Plugin < 1.05 - Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2015-6523
20 Jul 2015 — Cross-site request forgery (CSRF) vulnerability in the Portfolio plugin before 1.05 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the instagram-portfolio page in wp-admin/options-general.php. Vulnerabilidad CSRF en el plugin Portfolio en versiones anteriores a 1.05 para WordPress, permite a atacantes remotos secuestrar la autenticación de los administradores para peticiones que tienen un impacto no especificado... • http://seclists.org/fulldisclosure/2015/Jul/104 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2015-9462 – Awesome Filterable Portfolio < 1.9 - Blind SQL Injection
https://notcve.org/view.php?id=CVE-2015-9462
07 Jul 2015 — The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter. El plugin awesome-filterable-portfolio versiones anteriores a 1.9 para WordPress, presenta una inyección SQL de la función afp_get_new_category_page por medio del parámetro cat_id. • http://cinu.pl/research/wp-plugins/mail_082287dbf7a24d415ff71581fc248330.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •