Vulnerabilities > Kibokolabs

DATE CVE VULNERABILITY TITLE RISK
2022-12-02 CVE-2022-4215 Unspecified vulnerability in Kibokolabs Chained Quiz
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping.
network
low complexity
kibokolabs
6.1
2022-12-02 CVE-2022-4216 Unspecified vulnerability in Kibokolabs Chained Quiz
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'facebook_appid' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping.
network
low complexity
kibokolabs
4.8
2022-12-02 CVE-2022-4217 Unspecified vulnerability in Kibokolabs Chained Quiz
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping.
network
low complexity
kibokolabs
4.8
2022-12-02 CVE-2022-4218 Unspecified vulnerability in Kibokolabs Chained Quiz
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4.
network
low complexity
kibokolabs
4.3
2022-12-02 CVE-2022-4219 Unspecified vulnerability in Kibokolabs Chained Quiz
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4.
network
low complexity
kibokolabs
4.3
2022-12-02 CVE-2022-4220 Unspecified vulnerability in Kibokolabs Chained Quiz
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4.
network
low complexity
kibokolabs
4.3
2021-10-11 CVE-2021-24690 Cross-site Scripting vulnerability in Kibokolabs Chained Quiz
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
network
low complexity
kibokolabs CWE-79
5.4
2021-09-10 CVE-2021-38358 Cross-site Scripting vulnerability in Kibokolabs Moolamojo 0.7.4.1
The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.4.1.
network
low complexity
kibokolabs CWE-79
6.1
2021-09-09 CVE-2021-38317 Cross-site Scripting vulnerability in Kibokolabs Konnichiwa
The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in the ~/views/subscriptions.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.8.3.
network
low complexity
kibokolabs CWE-79
6.1
2020-03-10 CVE-2018-14502 SQL Injection vulnerability in Kibokolabs Chained Quiz
controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
network
low complexity
kibokolabs CWE-89
critical
9.8