Vulnerabilities > Rarathemes

DATE CVE VULNERABILITY TITLE RISK
2023-04-23 CVE-2023-24404 Cross-site Scripting vulnerability in Rarathemes Vryasage Marketing Performance
Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions.
network
low complexity
rarathemes CWE-79
6.1
2022-04-29 CVE-2022-29451 Unrestricted Upload of File with Dangerous Type vulnerability in Rarathemes Rara ONE Click Demo Import
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.
6.8