Filtered by vendor Tribulant
Subscriptions
Total
34 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-4797 | 1 Tribulant | 1 Newsletters | 2025-06-11 | 7.2 High |
| The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server. | ||||
| CVE-2014-5460 | 1 Tribulant | 1 Tibulant Slideshow Gallery | 2025-04-12 | N/A |
| Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/. | ||||
| CVE-2024-35718 | 1 Tribulant | 1 Newsletters | 2024-11-21 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.5. | ||||
| CVE-2023-28497 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | 5.4 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions. | ||||
| CVE-2021-24882 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | 4.8 Medium |
| The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | ||||
| CVE-2020-35932 | 1 Tribulant | 1 Newsletter | 2024-11-21 | 7.5 High |
| Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes. | ||||
| CVE-2019-15828 | 1 Tribulant | 1 One Click Ssl | 2024-11-21 | N/A |
| The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. | ||||
| CVE-2019-14788 | 1 Tribulant | 1 Newsletters | 2024-11-21 | 8.8 High |
| wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value. | ||||
| CVE-2019-14787 | 1 Tribulant | 1 Newsletters | 2024-11-21 | 5.4 Medium |
| The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter. | ||||
| CVE-2018-20987 | 1 Tribulant | 1 Newsletters | 2024-11-21 | N/A |
| The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. | ||||
| CVE-2018-18019 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | N/A |
| XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter. | ||||
| CVE-2018-18018 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | N/A |
| SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter. | ||||
| CVE-2018-18017 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | N/A |
| XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter. | ||||
| CVE-2018-17946 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | N/A |
| The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter. | ||||
ReportizFlow