Filtered by vendor Daily Prayer Time Project
Subscribe
Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-27632 | 1 Daily Prayer Time Project | 1 Daily Prayer Time | 2023-11-17 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.03.08 versions. | |||||
CVE-2023-27631 | 1 Daily Prayer Time Project | 1 Daily Prayer Time | 2023-06-28 | N/A | 5.4 MEDIUM |
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.05.04 versions. | |||||
CVE-2022-0785 | 1 Daily Prayer Time Project | 1 Daily Prayer Time | 2022-04-27 | 7.5 HIGH | 9.8 CRITICAL |
The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection | |||||
CVE-2021-24523 | 1 Daily Prayer Time Project | 1 Daily Prayer Time | 2021-09-23 | 3.5 LOW | 5.4 MEDIUM |
The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputting them in the page, leading to Authenticated Stored Cross-Site Scripting issues. |