Carrcommunications
Carrcommunications Rsvpmaker: vulnerabilidades y CVE
Carrcommunications Rsvpmaker tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-31552 | Crítica (9.3) | 0.51% | — | 1 abr 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.This issue affects RSVPMarker : from n/a through <= 11.6.7. |
| CVE-2025-24600 | Media (5.3) | 0.29% | — | 27 ene 2025 | Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5. |
| CVE-2024-50531 | Crítica (9.8) | 0.51% | — | 4 nov 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters:… |
| CVE-2023-25054 | Crítica (9.8) | 0.85% | — | 29 dic 2023 | Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.6.6. |
| CVE-2023-41652 | Crítica (9.8) | 1.0% | — | 3 nov 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6. |
| CVE-2023-25047 | Alta (7.2) | 0.68% | — | 31 oct 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3. |
| CVE-2023-25045 | Alta (7.2) | 0.55% | — | 31 oct 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3. |
| CVE-2023-27617 | Media (4.8) | 0.37% | — | 27 sept 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. |
| CVE-2023-27616 | Media (6.1) | 0.39% | — | 27 sept 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. |
| CVE-2023-29095 | Alta (7.2) | 0.90% | — | 10 jul 2023 | Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions. |
| CVE-2022-1768 | Alta (7.5) | 13% | — | 13 jun 2022 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file.… |
| CVE-2022-1505 | Alta (7.5) | 1.9% | — | 10 may 2022 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file.… |
| CVE-2022-1453 | Alta (7.5) | 6.9% | — | 10 may 2022 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes… |
| CVE-2021-24371 | Baja (2.7) | 1.0% | — | 2 ago 2021 | The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a… |
| CVE-2019-15646 | Crítica (9.8) | 2.3% | — | 27 ago 2019 | The rsvpmaker plugin before 6.2 for WordPress has SQL injection. |
| CVE-2018-21004 | Crítica (9.8) | 2.2% | — | 27 ago 2019 | The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection. |