Vulnerabilities and security researches formaterial-dashboard material-dashboard
Direction: ascendingApr 03, 2025
Material Dashboard # CVE-2025-31095
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 01, 2025
- Research Description
- Authentication Bypass Using an Alternate Path or Channel vulnerability in Hossein Material Dashboard material-dashboard allows Authentication Bypass.This issue affects Material Dashboard: from n/a through <= 1.4.5.
- Affected versions
-
max 1.4.6.
- Status
-
vulnerable
Apr 14, 2025
Material Dashboard # CVE-2025-31014
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 11, 2025
- Research Description
- Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hossein Material Dashboard material-dashboard allows PHP Local File Inclusion.This issue affects Material Dashboard: from n/a through <= 1.4.5.
- Affected versions
-
max 1.4.6.
- Status
-
vulnerable
Apr 29, 2025
Material Dashboard # CVE-2025-32486
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 09, 2025
- Research Description
- Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.
- Affected versions
-
max 1.4.7.
- Status
-
vulnerable
Jun 13, 2026
Material Dashboard # CVE-2025-31097
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 02, 2025
- Research Description
- Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hossein Material Dashboard material-dashboard allows PHP Local File Inclusion.This issue affects Material Dashboard: from n/a through <= 1.4.5.
- Affected versions
-
max 1.4.6.
- Status
-
vulnerable
Aug 06, 2026
Material Dashboard # CVE-2026-6079
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 05, 2026
- Research Description
- The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks (potentially exposing PII), execute arbitrary tasks, and delete any task via the public_amd_ajax_handler AJAX action.
- Affected versions
-
max 1.4.11.
- Status
-
vulnerable