cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formaterial-dashboard material-dashboard

Direction: ascending
Apr 03, 2025

Material Dashboard # CVE-2025-31095

CVE, Research URL

CVE-2025-31095

Application

Material Dashboard

Date
Apr 01, 2025
Research Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Hossein Material Dashboard material-dashboard allows Authentication Bypass.This issue affects Material Dashboard: from n/a through <= 1.4.5.
Affected versions
max 1.4.6.
Status
vulnerable
Apr 14, 2025

Material Dashboard # CVE-2025-31014

CVE, Research URL

CVE-2025-31014

Application

Material Dashboard

Date
Apr 11, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hossein Material Dashboard material-dashboard allows PHP Local File Inclusion.This issue affects Material Dashboard: from n/a through <= 1.4.5.
Affected versions
max 1.4.6.
Status
vulnerable
Apr 29, 2025

Material Dashboard # CVE-2025-32486

CVE, Research URL

CVE-2025-32486

Application

Material Dashboard

Date
Sep 09, 2025
Research Description
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.
Affected versions
max 1.4.7.
Status
vulnerable
Jun 13, 2026

Material Dashboard # CVE-2025-31097

CVE, Research URL

CVE-2025-31097

Application

Material Dashboard

Date
Apr 02, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hossein Material Dashboard material-dashboard allows PHP Local File Inclusion.This issue affects Material Dashboard: from n/a through <= 1.4.5.
Affected versions
max 1.4.6.
Status
vulnerable
Aug 06, 2026

Material Dashboard # CVE-2026-6079

CVE, Research URL

CVE-2026-6079

Application

Material Dashboard

Date
Aug 05, 2026
Research Description
The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks (potentially exposing PII), execute arbitrary tasks, and delete any task via the public_amd_ajax_handler AJAX action.
Affected versions
max 1.4.11.
Status
vulnerable