Learnpress
by Thimpress
Source repositories
CVEs (45)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36516 | 0.00 | — | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3. | |||
| CVE-2021-39348 | 0.00 | — | 0.05 | Oct 21, 2021 | The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web… | |||
| CVE-2018-16173 | 0.00 | — | 0.01 | Jan 9, 2019 | Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2018-16174 | 0.00 | — | 0.01 | Jan 9, 2019 | Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |||
| CVE-2018-16175 | 0.00 | — | 0.01 | Jan 9, 2019 | SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. |
- CVE-2023-36516Jun 19, 2024risk 0.00cvss —epss 0.00
Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.
- CVE-2021-39348Oct 21, 2021risk 0.00cvss —epss 0.05
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web…
- CVE-2018-16173Jan 9, 2019risk 0.00cvss —epss 0.01
Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2018-16174Jan 9, 2019risk 0.00cvss —epss 0.01
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2018-16175Jan 9, 2019risk 0.00cvss —epss 0.01
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
Page 3 of 3