Extension WordPress
Vulnérabilités Mingle Forum
Cette page rassemble les failles publiées pour Mingle Forum, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Mingle Forum
7 fiches
Mingle Forum <= 1.0.32.1 – SQL Injection
Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitrary SQL commands via the (1) memberid or (2) groupid parameters in a removemember…
[*, 1.0.33)
1.0.33
01/08/2014
Mingle Forum <= 1.0.32.1 – SQL Injection
Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) delete_usrgrp[] parameter in a delete_usergroups action, (2)…
*-1.0.32.1
1.0.33
01/08/2014
Mingle Forum < 1.0.34 – Unauthenticated SQL Injection
The Mingle Forum plugin for WordPress is vulnerable to generic SQL Injection in versions up to 1.0.34 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
[*, 1.0.34)
1.0.34
01/08/2014
Mingle Forum <= 1.0.33.3 – Stored Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers…
*-1.0.33.3
1.0.34
20/02/2013
Mingle Forum <= 1.0.33.3 – SQL Injection
Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action…
*-1.0.33.3
1.0.34
20/02/2013
Mingle Forum <= 1.0.34 – Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) modify user privileges or (2) conduct cross-site scripting…
*-1.0.34
1.0.35
02/01/2013
Mingle Forum <= 1.0.33 – Cross-Site Scripting
The Mingle Forum plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.0.33 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary…
*-1.0.33
1.0.33.2
15/05/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.