#PHP,webapps,
-
WordPress Plugin Easy Contact Form 1.1.7 - 'Name' Stored Cross-Site Scripting (XSS)
-
WordPress Plugin Autoptimize 2.7.6 - Authenticated Arbitrary File Upload (Metasploit)
-
Wordpress Plugin wpDiscuz 7.0.4 - Unauthenticated Arbitrary File Upload (Metasploit)
-
Cemetry Mapping and Information System 1.0 - Multiple Stored Cross-Site Scripting
-
WordPress Plugin Custom Global Variables 1.0.5 - 'name' Stored Cross-Site Scripting (XSS)
-
OpenCart 3.0.36 - ATO via Cross Site Request Forgery
-
Prestashop 1.7.7.0 - 'id_product' Time Based Blind SQL Injection
-
Gila CMS 2.0.0 - Remote Code Execution (Unauthenticated)
-
Cemetry Mapping and Information System 1.0 - Multiple SQL Injections
-
Life Insurance Management System 1.0 - 'client_id' SQL Injection
-
Voting System 1.0 - File Upload RCE (Authenticated Remote Code Execution)
-
Life Insurance Management System 1.0 - File Upload RCE (Authenticated)
-
Online Documents Sharing Platform 1.0 - 'user' SQL Injection
-
Apartment Visitors Management System 1.0 - 'email' SQL Injection
-
Nagios XI 5.7.5 - Multiple Persistent Cross-Site Scripting
-
CASAP Automated Enrollment System 1.0 - Authentication Bypass
-
Library System 1.0 - Authentication Bypass
-
MyBB Timeline Plugin 1.0 - Persistent Cross-Site Scripting
-
CASAP Automated Enrollment System 1.0 - 'route' Stored XSS
-
Simple College Website 1.0 - 'name' Sql Injection (Authentication Bypass)