Vulnerabilities (CVE)

Filtered by vendor Tribulant Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-28491 1 Tribulant 1 Slideshow Gallery 2023-12-27 N/A 7.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery LITE.This issue affects Slideshow Gallery LITE: from n/a through 1.7.6.
CVE-2023-28497 1 Tribulant 1 Slideshow Gallery 2023-11-15 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions.
CVE-2023-30478 1 Tribulant 1 Newsletters 2023-11-15 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
CVE-2020-35932 1 Tribulant 1 Newsletter 2021-01-11 6.0 MEDIUM 8.8 HIGH
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.
CVE-2019-15828 1 Tribulant 1 One Click Ssl 2019-09-05 6.8 MEDIUM 8.8 HIGH
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.
CVE-2019-14788 1 Tribulant 1 Newsletter 2019-08-22 6.5 MEDIUM 8.8 HIGH
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.