Cross Site Request Forgery (CSRF) vulnerability
24 January, 2025
Missing Authorization to Authenticated (Contributor+) Information Exposure vulnerability
12 December, 2024
Authenticated (Contributor+) Stored CrossSite Scripting via Shortcode vulnerability
4 June, 2024
Insecure Direct Object Reference to Arbitrary Attachment Deletion vulnerability
4 June, 2024
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
15 December, 2023