VYPR

Asgaros Forum plugin

by WordPress

CVEs (2)

  • CVE-2022-0411HigFeb 28, 2022
    risk 0.57cvss 8.8epss 0.02

    The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection

  • CVE-2022-41608MedMay 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum plugin <= 2.2.0 versions.