cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fornewstatpress newstatpress

Direction: ascending
Jun 07, 2024

NewStatPress # CVE-2015-9312

CVE, Research URL

CVE-2015-9312

Application

NewStatPress

Date
Aug 14, 2019
Research Description
The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
Affected versions
Min -, max -.
Status
vulnerable

NewStatPress # CVE-2015-9315

CVE, Research URL

CVE-2015-9315

Application

NewStatPress

Date
Aug 14, 2019
Research Description
The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
Affected versions
Min -, max -.
Status
vulnerable

NewStatPress # CVE-2015-4063

CVE, Research URL

CVE-2015-4063

Application

NewStatPress

Date
May 27, 2015
Research Description
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.
Affected versions
Min -, max -.
Status
vulnerable

NewStatPress # CVE-2022-0206

CVE, Research URL

CVE-2022-0206

Application

NewStatPress

Date
Feb 14, 2022
Research Description
The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
Affected versions
Min -, max -.
Status
vulnerable

NewStatPress # CVE-2017-18575

CVE, Research URL

CVE-2017-18575

Application

NewStatPress

Date
Aug 22, 2019
Research Description
The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
Affected versions
Min -, max -.
Status
vulnerable

NewStatPress # CVE-2015-4062

CVE, Research URL

CVE-2015-4062

Application

NewStatPress

Date
May 27, 2015
Research Description
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.
Affected versions
Min -, max -.
Status
vulnerable

NewStatPress # CVE-2015-9313

CVE, Research URL

CVE-2015-9313

Application

NewStatPress

Date
Aug 14, 2019
Research Description
The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
Affected versions
Min -, max -.
Status
vulnerable

NewStatPress # CVE-2015-9311

CVE, Research URL

CVE-2015-9311

Application

NewStatPress

Date
Aug 14, 2019
Research Description
The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
Affected versions
Min -, max -.
Status
vulnerable

NewStatPress # CVE-2015-9314

CVE, Research URL

CVE-2015-9314

Application

NewStatPress

Date
Aug 14, 2019
Research Description
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
Affected versions
Min -, max -.
Status
vulnerable