Genetechsolutions
Genetechsolutions PIE Register: vulnerabilidades y CVE
Genetechsolutions PIE Register tiene 18 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses4
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-103345 | Media (5.3) | 0.20% | — | 1 oct 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Shamim Rajani Pie Register pie-register allows Retrieve Embedded Sensitive Data.This issue affects Pie Register: from n/a through 3.8.4.13. |
| CVE-2026-10530 | Media (5.3) | 0.20% | — | 22 jun 2026 | The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an… |
| CVE-2026-3571 | Media (6.5) | 0.36% | — | 4 abr 2026 | The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions… |
| CVE-2026-24577 | Media (5.3) | 0.25% | — | 23 ene 2026 | Missing Authorization vulnerability in Genetech Products Pie Register pie-register allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pie Register: from n/a through <= 3.8.4.8. |
| CVE-2025-34077 | Crítica (10) | 16% | — | 9 jul 2025 | An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login… |
| CVE-2024-13818 | Alta (7.5) | 0.51% | — | 21 feb 2025 | The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all… |
| CVE-2024-27957 | Crítica (9.8) | 0.61% | — | 17 mar 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1. |
| CVE-2023-0552 | Media (5.4) | 24% | — | 27 feb 2023 | The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability |
| CVE-2022-4024 | Media (6.5) | 0.34% | — | 19 dic 2022 | The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their… |
| CVE-2021-24731 | Crítica (9.8) | 6.4% | — | 8 nov 2021 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in… |
| CVE-2021-24647 | Alta (8.1) | 9.8% | — | 8 nov 2021 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated… |
| CVE-2021-24239 | Media (6.1) | 1.6% | — | 22 abr 2021 | The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation… |
| CVE-2019-15659 | Crítica (9.8) | 1.9% | — | 27 ago 2019 | The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969. |
| CVE-2019-1010207 | Media (6.1) | 1.5% | — | 23 jul 2019 | Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The… |
| CVE-2018-10969 | Crítica (9.8) | 5.3% | — | 17 jun 2018 | SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid. |
| CVE-2015-7682 | Media (6.5) | 1.4% | — | 16 oct 2015 | Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1)… |
| CVE-2015-7377 | Media (4.3) | 4.4% | — | 16 oct 2015 | Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code… |
| CVE-2014-8802 | Media (5) | 7.4% | — | 23 ene 2015 | The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2)… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.