Sigmaplugin
Sigmaplugin Advanced Database Cleaner: vulnerabilidades y CVE
Sigmaplugin Advanced Database Cleaner tiene 9 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-7522 | Alta (8.8) | 0.82% | — | 20 may 2026 | The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' parameter. This makes it possible for authenticated… |
| CVE-2025-64357 | Media (4.3) | 0.12% | — | 31 oct 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allows Cross Site Request Forgery.This issue affects Advanced Database Cleaner: from n/a through <=… |
| CVE-2025-11497 | Media (4.3) | 0.23% | — | 25 oct 2025 | The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on the… |
| CVE-2024-0668 | Alta (7.2) | 1.1% | — | 5 feb 2024 | The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This… |
| CVE-2023-49764 | Alta (7.2) | 0.74% | — | 19 dic 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Younes JFR. Advanced Database Cleaner.This issue affects Advanced Database Cleaner: from n/a through 3.1.2. |
| CVE-2022-46813 | Alta (8.8) | 0.26% | — | 23 may 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions. |
| CVE-2022-2173 | Media (6.1) | 0.77% | — | 17 jul 2022 | The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting |
| CVE-2021-24921 | Media (6.1) | 0.80% | — | 21 feb 2022 | The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues |
| CVE-2021-24141 | Alta (7.2) | 1.2% | — | 18 mar 2021 | Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks. |