Vulnerabilities > Count PER DAY Project

DATE CVE VULNERABILITY TITLE RISK
2019-08-21 CVE-2012-6714 Cross-site Scripting vulnerability in Count PER DAY Project Count PER DAY
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
4.3
2019-06-15 CVE-2013-7472 Cross-site Scripting vulnerability in Count PER DAY Project Count PER DAY
The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.
4.3
2017-10-23 CVE-2015-5533 SQL Injection vulnerability in Count PER DAY Project Count PER DAY
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php.
network
low complexity
count-per-day-project CWE-89
6.5
2012-01-20 CVE-2012-0896 Path Traversal vulnerability in multiple products
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
5.0