Vulnerabilities and security researches formangboard mangboard
Direction: ascendingJun 06, 2024
Mang Board WP # CVE-2021-26609
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 26, 2021
- Research Description
- A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a remote attacker to steal user information.
- Affected versions
-
Min 1.0.0, max 1.9.9.
- Status
-
vulnerable
Mang Board WP # CVE-2023-44257
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 10, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Hometory Mang Board WP plugin <= 1.7.6 versions.
- Affected versions
-
max 1.8.2.
- Status
-
vulnerable
Mang Board WP # CVE-2024-22306
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 31, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Stored XSS.This issue affects Mang Board WP: from n/a through 1.7.7.
- Affected versions
-
max 1.7.8.
- Status
-
vulnerable
Mang Board WP # CVE-2024-30431
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 29, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.0.
- Affected versions
-
max 1.8.1.
- Status
-
vulnerable
Jan 08, 2025
Mang Board WP # CVE-2024-56296
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 07, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.4.
- Affected versions
-
max 1.8.5.
- Status
-
vulnerable
Apr 29, 2025
Mang Board WP # CVE-2025-3435
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 24, 2025
- Research Description
- The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
- Affected versions
-
max 1.8.7.
- Status
-
vulnerable