Home/Product/cridio listingpro
Product

cridio listingpro

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-39623
< 2.9.5
Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro allows Authentication Bypass.This issue affe
8.8HIGH
CVE-2024-39622
<= 2.9.4
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro list
9.3CRITICAL
CVE-2024-39620
<= 2.9.4
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro list
8.5HIGH
CVE-2024-38795
<= 2.9.4
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro list
9.3CRITICAL
CVE-2024-39624
< 2.9.5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro
8.5HIGH
CVE-2024-39621
< 2.9.5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro
8.0HIGH
CVE-2024-39619
< 2.9.5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro
9.0CRITICAL
CVE-2020-36723
< 2.6.1
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6
5.3MEDIUM
CVE-2020-36719
<= 2.6.1
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and
9.8CRITICAL
CVE-2019-19542
< 2.0.14.2
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.
5.4MEDIUM
CVE-2019-19541
< 2.0.14.2
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page
5.4MEDIUM
CVE-2019-19540
< 2.0.14.2
The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.
6.1MEDIUM
threatengine.sh