VYPR

Vendor CVEs

Kibokolabs

All CVEs

63 total · sorted by risk
  • CVE-2018-1002004MedDec 3, 2018
    risk 0.34cvss 4.8epss 0.03

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

  • CVE-2018-1002003MedDec 3, 2018
    risk 0.34cvss 4.8epss 0.03

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

  • CVE-2018-1002002MedDec 3, 2018
    risk 0.34cvss 4.8epss 0.03

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

  • CVE-2018-1002001MedDec 3, 2018
    risk 0.34cvss 4.8epss 0.03

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

  • CVE-2025-6236MedJul 10, 2025
    risk 0.31cvss 4.8epss 0.00

    The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2023-0545MedJun 5, 2023
    risk 0.31cvss 4.8epss 0.00

    The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2023-0844MedMar 13, 2023
    risk 0.31cvss 4.8epss 0.00

    The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2023-0548MedFeb 27, 2023
    risk 0.31cvss 4.8epss 0.01

    The Namaste! LMS WordPress plugin before 2.5.9.4 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2023-0543MedFeb 27, 2023
    risk 0.31cvss 4.8epss 0.00

    The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

  • CVE-2023-0429MedFeb 21, 2023
    risk 0.31cvss 4.8epss 0.00

    The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2024-0872MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.01

    The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.1 via the watu-userinfo shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive user…

  • CVE-2023-47686MedNov 16, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.2.2 versions.

  • CVE-2015-9418MedSep 26, 2019
    risk 0.28cvss 4.3epss 0.01

    The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.

Page 2 of 2