Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Getawesomesupport Subscribe
Filtered by product Awesome Support
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-3511 1 Getawesomesupport 1 Awesome Support 2022-11-29 N/A 6.5 MEDIUM
The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector
CVE-2022-38073 1 Getawesomesupport 1 Awesome Support 2022-09-22 N/A 5.4 MEDIUM
Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress.
CVE-2021-36919 1 Getawesomesupport 1 Awesome Support 2021-12-02 3.5 LOW 5.4 MEDIUM
Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee).
CVE-2019-20181 1 Getawesomesupport 1 Awesome Support 2020-01-14 3.5 LOW 4.8 MEDIUM
The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.
CVE-2015-9318 1 Getawesomesupport 1 Awesome Support 2019-08-22 5.0 MEDIUM 7.5 HIGH
The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
CVE-2015-9317 1 Getawesomesupport 1 Awesome Support 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.