Vulnerabilities > Crudlab

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2023-32966 Cross-Site Request Forgery (CSRF) vulnerability in Crudlab Jazz Popups
Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab Jazz Popups leads to Stored XSS.This issue affects Jazz Popups: from n/a through 1.8.7.
network
low complexity
crudlab CWE-352
6.1
2023-10-03 CVE-2023-40199 Cross-Site Request Forgery (CSRF) vulnerability in Crudlab WP Like Button
Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions.
network
low complexity
crudlab CWE-352
8.8
2023-07-18 CVE-2023-32965 Cross-site Scripting vulnerability in Crudlab Jazz Popups
Unauth.
network
low complexity
crudlab CWE-79
6.1
2019-07-05 CVE-2019-13344 Missing Authentication for Critical Function vulnerability in Crudlab WP Like Button
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings.
network
low complexity
crudlab CWE-306
5.0