Vulnerabilities and security researches forleyka leyka
Direction: ascendingJun 07, 2024
Leyka # CVE-2023-27450
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 21, 2023
- Research Description
- Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Leyka # CVE-2023-27442
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 22, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Leyka # CVE-2023-4917
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 13, 2023
- Research Description
- The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.3 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Leyka # CVE-2023-33325
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 30, 2023
- Research Description
- Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.30.1 versions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Leyka # CVE-2023-33327
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2024
- Research Description
- Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Leyka # CVE-2023-39314
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 10, 2023
- Research Description
- Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.30.2 versions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Leyka # CVE-2023-2995
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 20, 2023
- Research Description
- The Leyka WordPress plugin before 3.30.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 11, 2024
Leyka # CVE-2024-35683
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 11, 2024
- Research Description
- Missing Authorization vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through 3.31.1.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Oct 18, 2024
Leyka # CVE-2024-49252
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 16, 2024
- Research Description
- : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through 3.31.6.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Feb 18, 2025
Leyka # CVE-2025-26766
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 17, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows Stored XSS. This issue affects Leyka: from n/a through 3.31.8.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jul 03, 2025
Leyka # CVE-2025-53275
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 27, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows DOM-Based XSS. This issue affects Leyka: from n/a through 3.31.9.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jul 07, 2025
Leyka # CVE-2025-52805
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 04, 2025
- Research Description
- Path Traversal vulnerability in VaultDweller Leyka allows PHP Local File Inclusion. This issue affects Leyka: from n/a through 3.31.9.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable