Extension WordPress
Vulnérabilités CLUEVO LMS, E-Learning Platform
Cette page rassemble les failles publiées pour CLUEVO LMS, E-Learning Platform, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CLUEVO LMS, E-Learning Platform
4 fiches
CLUEVO LMS, E-Learning Platform <= 1.13.2 – Reflected Cross-Site Scripting
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.13.2. This makes…
*-1.13.2
1.13.3
08/01/2025
CLUEVO LMS, E-Learning Platform <= 1.13.2 – Cross-Site Request Forgery to Module Deletion
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce validation on the cluevo_render_module_ui() function. This makes it…
*-1.13.2
1.13.3
05/12/2024
CLUEVO LMS, E-Learning Platform <= 1.10.0 – Cross-Site Request Forgery
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.0. This is due to missing nonce validation on the save_settings() function. This makes it possible for unauthenticated…
*-1.10.0
1.11.0
17/08/2023
CLUEVO E-Learning Platform <= 1.8.0 – Authenticated Cross-Site Scripting
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed The CLUEVO E-Learning Platform…
[*, 1.8.1)
1.8.1
10/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.