Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ryoma Yamada

#21531of 53,635
11.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-8669
7.1
2025-02-26
WordPress · Simple:Press Forum · CVE-2024-10483
**Name of the Vulnerable Software and Affected Versions** The Simple:Press Forum WordPress plugin versions prior to 6.10.11 **Description** The issue is related to a Reflected Cross-Site Scripting problem. It occurs because a `parameter` is not properly sanitised and escaped before being outputted back in the page. **Recommendations** For versions prior to 6.10.11, update to version 6.10.11 or later to resolve the issue. As a temporary workaround, consider restricting the output of unsanitised parameters to minimize the risk of exploitation.
PT-2024-39870
4.1
2024-11-21
WordPress · Taskbuilder · CVE-2024-9828
**Name of the Vulnerable Software and Affected Versions** The Taskbuilder WordPress plugin versions prior to 3.0.5 **Description** The issue allows high privilege users, such as admins, to perform SQL Injection attacks due to the lack of sanitization of user input into the `load orders` parameter, which is then used in a SQL statement. **Recommendations** For versions prior to 3.0.5, update to version 3.0.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the `load orders` parameter to minimize the risk of exploitation.