Extension WordPress
Vulnérabilités All-In-One Security (AIOS) – Security and Firewall, page 2
Cette page rassemble les failles publiées pour All-In-One Security (AIOS) – Security and Firewall, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de All-In-One Security (AIOS) – Security and Firewall
27 fiches
All In One WP Security & Firewall <= 4.0.4 – Cross-Site Scripting
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
[*, 4.0.5)
4.0.5
22/02/2016
All In One WP Security & Firewall <= 3.9.7 – Cross-Site Scripting
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
[*, 3.9.8)
3.9.8
15/08/2015
All In One WP Security & Firewall <= 3.9.4 – Reflected Cross-Site Scripting
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
[*, 3.9.5)
3.9.5
20/04/2015
All In One WP Security & Firewall <= 3.9.0 – SQL Injection
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
[*, 3.9.1)
3.9.1
06/04/2015
All In One WP Security & Firewall <= 3.8.7 – SQL Injection
SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
[*, 3.8.8)
3.8.8
06/03/2015
All In One WP Security & Firewall <= 3.8.9 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not Found)…
*-3.8.9
3.9.0
06/03/2015
All In One WP Security & Firewall <= 3.8.2 – Authenticated Access or Cross-Site Request Forgery leading to SQL Injection via orderby, order Parameters
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec…
[*, 3.8.3)
3.8.3
24/09/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.