Lucene search

K

Oneclick Security Vulnerabilities

cve
cve

CVE-2024-29789

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem OneClick Chat to Order allows Stored XSS.This issue affects OneClick Chat to Order: from n/a through...

6.5CVSS

9.1AI Score

0.0004EPSS

2024-03-27 01:15 PM
28
cve
cve

CVE-2023-45889

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue exists because of an incomplete fix for...

6.1CVSS

6.2AI Score

0.001EPSS

2024-01-23 06:15 PM
9
cve
cve

CVE-2023-47546

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Walter Pinem OneClick Chat to Order plugin <= 1.0.4.2...

5.9CVSS

4.9AI Score

0.0004EPSS

2023-11-14 09:15 PM
11
cve
cve

CVE-2022-48612

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.7 allows remote attackers to inject JavaScript into any webpage, because a regular expression (validating whether a URL is controlled by ClassLink) is not present in all applicable...

6.1CVSS

6.1AI Score

0.001EPSS

2023-10-16 12:15 AM
26
cve
cve

CVE-2022-4760

The OneClick Chat to Order WordPress plugin before 1.0.4.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against...

5.4CVSS

5.3AI Score

0.001EPSS

2023-01-23 03:15 PM
36
cve
cve

CVE-2008-3026

SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id...

8.4AI Score

0.001EPSS

2008-07-07 06:41 PM
17
cve
cve

CVE-2007-2347

PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path...

7.6AI Score

0.066EPSS

2007-04-27 05:19 PM
28