cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcp-polls cp-polls

Direction: ascending
Jun 06, 2024

Polls CP # CVE-2015-9346

CVE, Research URL

CVE-2015-9346

Application

Polls CP

Date
Aug 27, 2019
Research Description
The cp-polls plugin before 1.0.5 for WordPress has XSS.
Affected versions
Min -, max -.
Status
vulnerable

Polls CP # CVE-2014-10395

CVE, Research URL

CVE-2014-10395

Application

Polls CP

Date
Aug 27, 2019
Research Description
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
Affected versions
Min -, max -.
Status
vulnerable

Polls CP # CVE-2024-24874

CVE, Research URL

CVE-2024-24874

Application

Polls CP

Date
May 17, 2024
Research Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71.
Affected versions
Min -, max -.
Status
vulnerable

Polls CP # CVE-2014-125091

CVE, Research URL

CVE-2014-125091

Application

Polls CP

Date
Mar 05, 2023
Research Description
A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the argument lu leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.0.2 is able to address this issue. The name of the patch is 6d7168cbf12d1c183bacc5cd5678f6f5b0d518d2. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-222268.
Affected versions
Min -, max -.
Status
vulnerable

Polls CP # CVE-2024-24873

CVE, Research URL

CVE-2024-24873

Application

Polls CP

Date
May 17, 2024
Research Description
: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.
Affected versions
Min -, max -.
Status
vulnerable
Sep 28, 2024

Polls CP # CVE-2024-47297

CVE, Research URL

CVE-2024-47297

Application

Polls CP

Date
Oct 06, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople CP Polls allows Reflected XSS.This issue affects CP Polls: from n/a through 1.0.74.
Affected versions
Min -, max -.
Status
vulnerable
May 19, 2025

Polls CP # CVE-2024-8851

CVE, Research URL

CVE-2024-8851

Application

Polls CP

Date
May 16, 2025
Research Description
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).
Affected versions
Min -, max -.
Status
vulnerable

Polls CP # CVE-2024-8854

CVE, Research URL

CVE-2024-8854

Application

Polls CP

Date
May 16, 2025
Research Description
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).
Affected versions
Min -, max -.
Status
vulnerable