Vulnerabilities > Genetechsolutions

DATE CVE VULNERABILITY TITLE RISK
2023-02-27 CVE-2023-0552 Unspecified vulnerability in Genetechsolutions PIE Register
The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability
network
low complexity
genetechsolutions
5.4
2022-12-19 CVE-2022-4024 Missing Authorization vulnerability in Genetechsolutions PIE Register
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)
network
low complexity
genetechsolutions CWE-862
6.5
2021-11-08 CVE-2021-24647 Improper Authentication vulnerability in Genetechsolutions PIE Register
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
network
high complexity
genetechsolutions CWE-287
8.1
2021-11-08 CVE-2021-24731 SQL Injection vulnerability in Genetechsolutions PIE Register
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.
network
low complexity
genetechsolutions CWE-89
critical
9.8
2021-04-22 CVE-2021-24239 Cross-site Scripting vulnerability in Genetechsolutions PIE Register
The Pie Register – User Registration Forms.
network
low complexity
genetechsolutions CWE-79
6.1
2019-08-27 CVE-2019-15659 SQL Injection vulnerability in Genetechsolutions PIE Register
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
network
low complexity
genetechsolutions CWE-89
7.5
2019-07-23 CVE-2019-1010207 Cross-site Scripting vulnerability in Genetechsolutions PIE Register 3.0.15
Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS).
4.3
2018-06-17 CVE-2018-10969 SQL Injection vulnerability in Genetechsolutions PIE Register
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.
network
low complexity
genetechsolutions CWE-89
7.5
2015-10-16 CVE-2015-7682 SQL Injection vulnerability in Genetechsolutions PIE Register
Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.
network
low complexity
genetechsolutions CWE-89
6.5
2015-10-16 CVE-2015-7377 Cross-site Scripting vulnerability in Genetechsolutions PIE Register
Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.
4.3