cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formangboard mangboard

Direction: ascending
Jun 06, 2024

Mang Board WP # CVE-2021-26609

CVE, Research URL

CVE-2021-26609

Application

Mang Board WP

Date
Oct 26, 2021
Research Description
A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a remote attacker to steal user information.
Affected versions
Min 1.0.0, max 1.9.9.
Status
vulnerable

Mang Board WP # CVE-2023-44257

CVE, Research URL

CVE-2023-44257

Application

Mang Board WP

Date
Oct 10, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Hometory Mang Board WP plugin <= 1.7.6 versions.
Affected versions
max 1.8.2.
Status
vulnerable

Mang Board WP # CVE-2024-22306

CVE, Research URL

CVE-2024-22306

Application

Mang Board WP

Date
Jan 31, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Stored XSS.This issue affects Mang Board WP: from n/a through 1.7.7.
Affected versions
max 1.7.8.
Status
vulnerable

Mang Board WP # CVE-2024-30431

CVE, Research URL

CVE-2024-30431

Application

Mang Board WP

Date
Mar 29, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.0.
Affected versions
max 1.8.1.
Status
vulnerable
Jan 08, 2025

Mang Board WP # CVE-2024-56296

CVE, Research URL

CVE-2024-56296

Application

Mang Board WP

Date
Jan 07, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.4.
Affected versions
max 1.8.5.
Status
vulnerable
Apr 29, 2025

Mang Board WP # CVE-2025-3435

CVE, Research URL

CVE-2025-3435

Application

Mang Board WP

Date
Apr 24, 2025
Research Description
The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 1.8.7.
Status
vulnerable