Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.
Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or authorization checks. The callback route is authenticated, but it does not verify that the authenticated user has write access to the target workspace or Typebot before creating credentials in the workspace or updating Typebot group
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `logical.Auth` object in addition to an error message. This results in tokens being created with only the default policy, default TTL, and no entity information, which are hidden by the returned error message. No access to these tokens by the caller occurs and the au
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
Subscriber Path Traversal in Do Lasso <= 358 versions.
Subscriber SQL Injection in Do Lasso <= 358 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.