| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-1642 | MainWP Dashboard <= 4.6.0.1 - Cross-Site Request Forgery via posting_bulk | mainwp | MainWP Dashboard: Self-hosted WordPress Management for Agencies | Medium | 4.3 | 2024-03-13 15:26:41 | Deep Dive |
| CVE-2023-7198 | WPDashboardNotes < 1.0.11 - Unauthorised Deletion of Private Notes | Unknown | WP Dashboard Notes | 中危 | - | 2024-02-27 08:30:27 | Deep Dive |
| CVE-2023-51488 | WordPress Crowdsignal Dashboard – Polls, Surveys & more Plugin <= 3.0.11 is vulnerable to Cross Site Scripting (XSS) | Automattic, Inc. | Crowdsignal Dashboard – Polls, Surveys & more | High | 7.1 | 2024-02-10 08:27:19 | Deep Dive |
| CVE-2024-22290 | WordPress Custom Dashboard Widgets Plugin <= 1.3.1 is vulnerable to Cross Site Request Forgery (CSRF) | AboZain,O7abeeb,UnitOne | Custom Dashboard Widgets | High | 7.1 | 2024-01-31 11:56:24 | Deep Dive |
| CVE-2023-52128 | WordPress White Label Plugin <= 2.9.0 is vulnerable to Cross Site Request Forgery (CSRF) | WhiteWP | White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard | Medium | 4.3 | 2024-01-05 08:49:17 | Deep Dive |
| CVE-2023-50828 | WordPress Ultimate Dashboard Plugin <= 3.7.11 is vulnerable to Cross Site Scripting (XSS) | David Vongries | Ultimate Dashboard – Custom WordPress Dashboard | Medium | 5.9 | 2023-12-21 14:50:26 | Deep Dive |
| CVE-2023-38519 | WordPress MainWP Plugin <= 4.4.3.3 is vulnerable to SQL Injection | MainWP | MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance | High | 7.6 | 2023-12-20 13:48:05 | Deep Dive |
| CVE-2023-49743 | WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS) | Jeff Starr | Dashboard Widgets Suite | Medium | 5.9 | 2023-12-14 14:37:54 | Deep Dive |
| CVE-2023-40658 | Extension - deconf.net - Reflected XSS in Clicky Analytics Dashboard module for Joomla 1.0.0-1.3.1 | deconf.net | Clicky Analytics Dashboard module for Joomla | - | - | 2023-12-14 08:52:01 | Deep Dive |
| CVE-2023-50775 | Jenkins Deployment Dashboard Plugin 安全漏洞 | Jenkins Project | Jenkins Deployment Dashboard Plugin | - | - | 2023-12-13 17:30:21 | Deep Dive |
| CVE-2023-5710 | System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_constants) | qriouslad | System Dashboard | Medium | 4.3 | 2023-12-07 02:00:08 | Deep Dive |
| CVE-2023-5712 | System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_global_value) | qriouslad | System Dashboard | Medium | 4.3 | 2023-12-07 02:00:07 | Deep Dive |
| CVE-2023-5713 | System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_option_value) | qriouslad | System Dashboard | Medium | 4.3 | 2023-12-07 02:00:07 | Deep Dive |
| CVE-2023-5714 | System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_db_specs) | qriouslad | System Dashboard | Medium | 4.3 | 2023-12-07 02:00:06 | Deep Dive |
| CVE-2023-5711 | System Dashboard <= 2.8.8 - Missing Authorization to Information Disclosure (sd_php_info) | qriouslad | System Dashboard | Medium | 4.3 | 2023-12-07 02:00:05 | Deep Dive |
| CVE-2023-4726 | Ultimate Dashboard <= 3.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings | davidvongries | Ultimate Dashboard – Custom WordPress Dashboard | Medium | 4.4 | 2023-11-22 15:33:29 | Deep Dive |
| CVE-2023-6164 | MainWP Dashboard <= 4.5.1.2 - Authenticated(Administrator+) CSS Injection | mainwp | MainWP Dashboard: Self-hosted WordPress Management for Agencies | Low | 2.2 | 2023-11-22 15:33:28 | Deep Dive |
| CVE-2023-47184 | WordPress Admin Bar & Dashboard Access Control Plugin <= 1.2.8 is vulnerable to Cross Site Scripting (XSS) | Proper Fraction LLC. | Admin Bar & Dashboard Access Control | 中危 | - | 2023-11-06 09:56:41 | Deep Dive |
| CVE-2023-45064 | WordPress OPcache Dashboard Plugin <= 0.3.1 is vulnerable to Cross Site Scripting (XSS) | Daisuke Takahashi(Extend Wings) | OPcache Dashboard | High | 7.1 | 2023-10-18 08:44:18 | Deep Dive |
| CVE-2023-3361 | S3 credentials included when exporting elyra notebook | - | odh-dashboard | High | 7.7 | 2023-10-04 11:34:58 | Deep Dive |