Extension WordPress
Vulnérabilités Note Press
Cette page rassemble les failles publiées pour Note Press, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Note Press
4 fiches
Note Press <= 0.1.10 – Authenticated (Admin+) SQL Injection via Update
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection
*-0.1.10
Non indiqué
09/05/2022
Note Press <= 0.1.10 – Authenticated (Admin+) SQL Injection via ids Parameter
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections
*-0.1.10
Non indiqué
09/05/2022
Note Press <= 0.1.10 – Authenticated (Admin+) SQL Injection via id Parameter
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection.
*-0.1.10
Non indiqué
09/05/2022
Note Press < 0.1.2 – SQL Injection
The Note Press plugin for WordPress before 0.1.2 has a SQL injection vulnerability via the s parameter. This can be exploited by unauthenticated users.
[*, 0.1.2)
0.1.2
06/02/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.