Nxploit
37 exploits
Active since Jan 2024
Tainacan <= 0.21.7 - Authenticated Arbitrary File Read via Missing Authorization in get_file Function
CVSS 6.5
Crafthemes Demo Import <3.3 - File Upload
CVSS 7.2
Wux Blog Editor <3.0.0 - File Upload
CVSS 9.8
WebsiteinWP Blogpoet <= 1.0.3 - Missing Authorization
CVSS 6.5
WP BASE Booking <4.9.2 - Info Disclosure
CVSS 6.5
Hunk Companion WP <1.9.0 - Auth Bypass
CVSS 9.8
GPX Viewer <= 2.2.9 - Authenticated Arbitrary File Creation via gpxv_file_upload()
CVSS 8.8
Debug Tool < 2.2 - Unauthenticated Arbitrary File Creation via dbt_pull_image()
CVSS 9.8
Error Log Viewer By WP Guru <1.0.1.3 - Info Disclosure
CVSS 7.5
Concrete CMS 9.0.0-9.2.4 - Stored Cross-Site Scripting via Role Name Field
CVSS 2.0
EventON WordPress Plugin < 2.2.7 - Unauthenticated Email Address Disclosure via AJAX Action
CVSS 5.3
Jordy Meow AI Engine: ChatGPT Chatbot <= 1.9.98 - Unauthenticated Arbitrary File Upload
CVSS 10.0