Extension WordPress
Vulnérabilités CMS Commander – Manage Multiple Sites
Cette page rassemble les failles publiées pour CMS Commander – Manage Multiple Sites, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CMS Commander – Manage Multiple Sites
3 fiches
CMS Commander <= 2.288 – Authenticated (Custom+) SQL Injection via 'or_blogname' Parameter
The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is due to insufficient escaping on the user supplied parameters and…
*-2.288
Non indiqué
20/03/2026
CMS Commander <= 2.287 – Authorization Bypass through Use of Insufficiently Unique Cryptographic Signature
The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and including, 2.287. This makes it possible for unauthenticated…
*-2.287
2.288
19/06/2023
CMS Commander – Manage Multiple Sites Plugin <= 2.21 – PHP Object Injection
The CMS Commander – Manage Multiple Sites plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.21 via deserialization of untrusted input in the cmsc_authenticate() function. This allows unauthenticated attackers to inject…
[*, 2.22)
2.22
01/06/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.