Vulnerabilities > Bowo > System Dashboard > 2.8.7

DATE CVE VULNERABILITY TITLE RISK
2025-01-30 CVE-2024-12299 Cross-site Scripting vulnerability in Bowo System Dashboard 2.8.7
The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping.
network
low complexity
bowo CWE-79
6.1
2023-12-07 CVE-2023-5710 Missing Authorization vulnerability in Bowo System Dashboard 2.8.7
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7.
network
low complexity
bowo CWE-862
4.3
2023-12-07 CVE-2023-5711 Missing Authorization vulnerability in Bowo System Dashboard 2.8.7
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7.
network
low complexity
bowo CWE-862
4.3
2023-12-07 CVE-2023-5712 Missing Authorization vulnerability in Bowo System Dashboard 2.8.7
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7.
network
low complexity
bowo CWE-862
4.3
2023-12-07 CVE-2023-5713 Missing Authorization vulnerability in Bowo System Dashboard 2.8.7
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7.
network
low complexity
bowo CWE-862
4.3
2023-12-07 CVE-2023-5714 Missing Authorization vulnerability in Bowo System Dashboard 2.8.7
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7.
network
low complexity
bowo CWE-862
4.3