← Back

Ostenta

ostenta

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Yawpp
yawpp

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ostenta
1Yawpp
Nov 21, 2024
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.
1Ostenta
1Yawpp
May 6, 2026
Aug 6, 2014
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php o...Show more
Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php or (2) admin_update.php, as demonstrated by the id parameter in the update action to wp-admin/admin.php.Show less