Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Usabilitydynamics Subscribe
Total 7 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1202 1 Usabilitydynamics 1 Wp-crm 2022-06-17 6.8 MEDIUM 7.8 HIGH
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
CVE-2016-11011 1 Usabilitydynamics 1 Wp-invoice 2019-09-20 4.0 MEDIUM 6.5 MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
CVE-2016-11009 1 Usabilitydynamics 1 Wp-invoice 2019-09-20 5.0 MEDIUM 5.3 MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
CVE-2016-11010 1 Usabilitydynamics 1 Wp-invoice 2019-09-20 5.0 MEDIUM 5.3 MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
CVE-2016-11007 1 Usabilitydynamics 1 Wp-invoice 2019-09-20 5.0 MEDIUM 5.3 MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
CVE-2016-11008 1 Usabilitydynamics 1 Wp-invoice 2019-09-20 5.0 MEDIUM 5.3 MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
CVE-2016-11006 1 Usabilitydynamics 1 Wp-invoice 2019-09-20 5.0 MEDIUM 5.3 MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.