Lucene search

K

Opt Security Vulnerabilities

cve
cve

CVE-2024-2336

The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...

6.4CVSS

6AI Score

0.0004EPSS

2024-04-09 07:15 PM
35
cve
cve

CVE-2023-52192

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keap Keap Official Opt-in Forms allows Stored XSS.This issue affects Keap Official Opt-in Forms: from n/a through...

6.5CVSS

5.4AI Score

0.0004EPSS

2024-02-01 10:15 AM
20
cve
cve

CVE-2023-6941

The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite...

4.8CVSS

4.7AI Score

0.0004EPSS

2024-01-15 04:15 PM
23
cve
cve

CVE-2022-47597

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Popup Maker Popup Maker – Popup for opt-ins, lead gen, & more.This issue affects Popup Maker – Popup for opt-ins, lead gen, & more: from n/a through...

7.5CVSS

7.5AI Score

0.001EPSS

2023-12-20 06:15 PM
10
cve
cve

CVE-2023-25712

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-Buddy Google Analytics Opt-Out plugin <= 2.3.4...

5.9CVSS

4.8AI Score

0.0005EPSS

2023-04-07 01:15 PM
23
cve
cve

CVE-2022-41134

Cross-Site Request Forgery (CSRF) in OptinlyHQ Optinly – Exit Intent, Newsletter Popups, Gamification & Opt-in Forms plugin <= 1.0.15...

8.8CVSS

8.8AI Score

0.001EPSS

2023-02-13 05:15 PM
19
cve
cve

CVE-2022-2123

The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam...

4.3CVSS

4.6AI Score

0.001EPSS

2022-07-11 01:15 PM
29
4
cve
cve

CVE-2022-1104

The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is...

4.8CVSS

4.6AI Score

0.001EPSS

2022-05-09 05:15 PM
52
6
cve
cve

CVE-2015-7517

Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in...

9.8CVSS

10AI Score

0.002EPSS

2017-08-29 03:29 PM
29
cve
cve

CVE-2006-4239

PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CRM_inc...

7.9AI Score

0.086EPSS

2006-08-21 06:04 PM
22
cve
cve

CVE-2004-2368

PHP remote file inclusion vulnerability in header.php in Opt-X 0.7.2 allows remote attackers to execute arbitrary PHP code via the systempath...

8AI Score

0.061EPSS

2005-08-16 04:00 AM
112
cve
cve

CVE-2003-0390

Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as...

7.6AI Score

0.0004EPSS

2003-07-02 04:00 AM
25