Vulnerabilities (CVE)

Filtered by vendor Loginizer Subscribe
Filtered by product Loginizer
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-27615 1 Loginizer 1 Loginizer 2020-10-23 7.5 HIGH 9.8 CRITICAL
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
CVE-2017-12650 1 Loginizer 1 Loginizer 2017-08-15 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.