Extension WordPress
Vulnérabilités GD Rating System
Cette page rassemble les failles publiées pour GD Rating System, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de GD Rating System
14 fiches
GD Rating System <= 3.7 – Authenticated (Contributor+) SQL Injection
The GD Rating System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-3.7
3.7.1
02/07/2026
GD Rating System <= 3.6.2 – Unauthenticated SQL Injection
The GD Rating System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-3.6.2
3.7
29/04/2026
GD Rating System <= 3.6.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via extra_class Parameter
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.6.1
3.6.2
19/11/2024
GD Rating System <= 3.6 – Authenticated (Contributor+) Local File Inclusion
The GD Rating System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary…
*-3.6
3.6.1
11/07/2024
GD Rating System <= 3.5.0 – Unauthenticated Stored Cross-Site Scripting via IP
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address values in all versions up to, and including, 3.5.0 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.5.0
3.5.1
08/01/2024
GD Rating System <= 2.3 – Directory Traversal
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
[*, 2.3.1)
2.3.1
08/01/2018
GD Rating System <= 2.3 – Cross-Site Scripting
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
[*, 2.3.1)
2.3.1
08/01/2018
GD Rating System <= 2.3 – Cross-Site Scripting
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
[*, 2.3.1)
2.3.1
08/01/2018
GD Rating System <= 2.3 – Cross-Site Scripting
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
[*, 2.3.1)
2.3.1
08/01/2018
GD Rating System <= 2.3 – Cross-Site Scripting
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
[*, 2.3.1)
2.3.1
08/01/2018
GD Rating System <= 2.3 – Directory Traversal
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
[*, 2.3.1)
2.3.1
08/01/2018
GD Rating System <= 2.3 – Directory Traversal
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
[*, 2.3.1)
2.3.1
08/01/2018
GD Rating System <= 2.3 – Directory Traversal
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
[*, 2.3.1)
2.3.1
08/01/2018
GD Rating System < 2.1 – Reflected Cross-Site Scripting
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php via the status parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user…
[*, 2.1)
2.1
23/02/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.