Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
116027.3%CRITICAL

Related CVEs

16
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2024-37440Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.4.MEDIUM4.325.0%Nov 1, 2024
CVE-2024-37418Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.6.CRITICAL9.941.2%Jul 9, 2024
CVE-2024-35764Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.4.MEDIUM5.423.6%Jun 21, 2024
CVE-2024-35637Server-Side Request Forgery (SSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.3.6.MEDIUM4.415.5%Jun 3, 2024
CVE-2024-31281Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.6.MEDIUM6.326.1%May 17, 2024
CVE-2024-34828Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.32.MEDIUM4.316.5%May 14, 2024
CVE-2024-32090Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.0.27.MEDIUM4.311.9%Apr 15, 2024
CVE-2024-31280Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.5.HIGH8.845.5%Apr 7, 2024
CVE-2024-30505Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.18.MEDIUM6.537.1%Mar 29, 2024
CVE-2024-30493Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.7.MEDIUM4.311.7%Mar 29, 2024
CVE-2024-30244Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.0.27.HIGH8.846.9%Mar 28, 2024
CVE-2024-30197Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.0.26.MEDIUM5.423.8%Mar 27, 2024
CVE-2024-30193Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.17.MEDIUM5.423.8%Mar 27, 2024
CVE-2023-38515Server-Side Request Forgery (SSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 3.7.56.MEDIUM4.933.7%Nov 13, 2023
CVE-2023-34021Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.29 versions.MEDIUM6.1Jun 23, 2023
CVE-2022-0833The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB dataMEDIUM4.3Mar 28, 2022