Vasyltech
vasyltech
9 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unaut...Show more |
1Vasyltech 1Advanced Access Manager Jun 17, 2026 Mar 19, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20. |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This iss...Show more |
1Vasyltech 1Advanced Access Manager Jun 17, 2026 Dec 29, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Con...Show more |
1Vasyltech 1Advanced Access Manager Jun 17, 2026 Dec 29, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This iss...Show more |
1Vasyltech 1Advanced Access Manager Jun 17, 2026 Nov 23, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html cap...Show more |
1Vasyltech 1Advanced Access Manager Jun 17, 2026 Jan 1, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether...Show more |
1Vasyltech 1Advanced Access Manager Jun 17, 2026 Jan 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security prob...Show more |
1Vasyltech 1Advanced Access Manager Nov 21, 2024 Jan 13, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability |