tomorroisnew
34 exploits
Active since Aug 2021
DW Question & Answer Pro <1.3.4 - Info Disclosure
DW Question & Answer Pro <1.3.4 - CSRF
wpDiscuz < 7.3.4 - Cross-Site Request Forgery in Comment Management
BP Better Messages < 1.9.9.41 - Reflected Cross-Site Scripting via Subject Parameter
BP Better Messages <1.9.9.41 - CSRF
Support Board < 3.3.6 - Cross-Site Request Forgery via include/ajax.php
Tab WordPress <1.3.2 - Info Disclosure
AnyComment WordPress <0.3.5 - Open Redirect
SupportCandy WordPress <2.2.5 - CSRF
SupportCandy WordPress <2.2.7 - CSRF
D-Link DIR-615 C2 3.03WW - Buffer Overflow via ping_ipaddr Parameter
Tenda AC10-1200 <15.03.06.23 - Buffer Overflow
Tenda AC10-1200 <15.03.06.23 - Buffer Overflow
AnyComment WordPress <0.2.18 - CSRF
AnyComment WP <0.2.18 - Privilege Escalation
WP Voting Contest < 3.0 - Reflected Cross-Site Scripting via post_id Parameter
FormCraft WP <3.8.28 - Server-Side Request Forgery via URL Parameter
MapSVG < 6.2.20 - Unauthenticated SQL Injection via REST Endpoint
shareaholic < 9.7.6 - Unauthenticated Information Disclosure via AJAX Action
Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Stored Cross-Site Scripting via SVG File Upload
Plezi WordPress Plugin < 1.0.3 - Unauthenticated Stored Cross-Site Scripting via REST Endpoint
spirit < 0.12.3 - Open Redirect
livehelperchat/livehelperchat <3.97 - SSRF
showdoc < 2.10.4 - Stored Cross-Site Scripting via File Upload
HubSpot WordPress Plugin < 8.8.15 - Server-Side Request Forgery via Proxy REST Endpoint