Vulnerabilities (CVE)

Filtered by vendor Groundhogg Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-34178 1 Groundhogg 1 Groundhogg 2023-11-15 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11 versions.
CVE-2023-34179 1 Groundhogg 1 Groundhogg 2023-11-13 N/A 7.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Inc. Groundhogg allows SQL Injection.This issue affects Groundhogg: from n/a through 2.7.11.
CVE-2019-15647 1 Groundhogg 1 Groundhogg 2019-08-29 6.5 MEDIUM 8.8 HIGH
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.