VYPR
Vendor

Usabilitydynamics

Products
2
CVEs
8
Across products
8
Status
Private

Products

2

Recent CVEs

8
  • CVE-2022-1202HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.01

    The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.

  • CVE-2016-11011MedSep 20, 2019
    risk 0.42cvss 6.5epss 0.01

    The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.

  • CVE-2022-1617MedJan 16, 2024
    risk 0.40cvss 6.1epss 0.00

    The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them

  • CVE-2016-11010MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.

  • CVE-2016-11009MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.

  • CVE-2016-11008MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.

  • CVE-2016-11007MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.

  • CVE-2016-11006MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.