CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vcita 1Crm And Lead Management By Vcita Jun 5, 2025 Mar 26, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler' and 'vCitaSchedulingCalendar' shortcodes in all versions up to, and includin...Show more |
1Vcita 1Crm And Lead Management By Vcita Apr 8, 2026 Mar 13, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae() function in all versions up to, and including,...Show more |
1Vcita 1Crm And Lead Management By Vcita Apr 8, 2026 Jun 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.0. This is due to missing nonce validation in the vcita-callback.php file. This...Show more |
1Vcita 1Crm And Lead Management By Vcita Apr 8, 2026 Jun 3, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.2 due to insufficient input sanitization and output e...Show more |