Vulnerabilities > LWS

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-43962 Missing Authorization vulnerability in LWS Affiliation
Missing Authorization vulnerability in LWS LWS Affiliation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LWS Affiliation: from n/a through 2.3.4.
network
low complexity
lws CWE-862
8.8
2023-11-22 CVE-2023-27453 Cross-Site Request Forgery (CSRF) vulnerability in LWS Tools
Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.3.1 versions.
network
low complexity
lws CWE-352
8.8
2023-11-09 CVE-2023-34025 Cross-Site Request Forgery (CSRF) vulnerability in LWS Hide Login
Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Hide Login plugin <= 2.1.6 versions.
network
low complexity
lws CWE-352
8.8
2023-07-11 CVE-2023-35774 Cross-Site Request Forgery (CSRF) vulnerability in LWS Tools
Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.4.1 versions.
network
low complexity
lws CWE-352
8.8
2023-07-11 CVE-2023-35781 Cross-Site Request Forgery (CSRF) vulnerability in LWS Cleaner
Cross-Site Request Forgery (CSRF) vulnerability in LWS Cleaner plugin <= 2.3.0 versions.
network
low complexity
lws CWE-352
8.8