plugin

System Dashboard Vulnerabilities

22 known security issues reported for the System Dashboard WordPress plugin. Most recent disclosed Sep 25, 2025.

1 high 10 medium

Running System Dashboard on your site? Check whether your installed version is affected.

Scan your site free

System Dashboard <= 2.8.20 - Cross-Site Request Forgery

medium

The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.20. This is due to missing nonce validation on the sd_toggle_logs() function. This makes it possible for unauthenticated attackers to toggle critical logging settings including Page Access Log...

CVSS:
4.3
Affected:
up to 2.8.20
Fixed in:
2.8.21
Disclosed:
Sep 25, 2025

CVE-2025-10377 on NVD →

System Dashboard [system-dashboard] < 2.8.19

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects System Dashboard: from n/a through 2.8.18.

Affected:
up to 2.8.19
Fixed in:
2.8.19
Disclosed:
Feb 25, 2025

CVE-2025-26911 on NVD →

System Dashboard <= 2.8.18 - Authenticated (Subscriber+) Sensitive Information Exposure

medium

The System Dashboard plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 2.8.18
Fixed in:
2.8.19
Disclosed:
Feb 23, 2025

CVE-2025-26911 on NVD →

System Dashboard <= 2.8.17 - Reflected Cross-Site Scripting via Filename Parameter

medium

The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 2.8.17
Fixed in:
2.8.18
Disclosed:
Jan 30, 2025

CVE-2024-12299 on NVD →

System Dashboard [system-dashboard] < 2.8.18

unknown

[en] The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 2.8.18
Fixed in:
2.8.18
Disclosed:
Jan 30, 2025

CVE-2024-12299 on NVD →

System Dashboard [system-dashboard] < 2.8.15

unknown

[en] The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

Affected:
up to 2.8.15
Fixed in:
2.8.15
Disclosed:
Dec 10, 2024

CVE-2024-10708 on NVD →

System Dashboard [system-dashboard] < 2.8.15

unknown

[en] The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

Affected:
up to 2.8.15
Fixed in:
2.8.15
Disclosed:
Dec 10, 2024

CVE-2024-11107 on NVD →

System Dashboard <= 2.8.14 - Unauthenticated Stored Cross-Site Scripting

high

The System Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
7.2
Affected:
up to 2.8.14
Fixed in:
2.8.15
Disclosed:
Nov 19, 2024

CVE-2024-11107 on NVD →

System Dashboard <= 2.8.14 - Authenticated (Admin+) Arbitrary File Read

medium

The System Dashboard plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.14 via the 'sd_viewer' action. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain...

CVSS:
4.9
Affected:
up to 2.8.14
Fixed in:
2.8.15
Disclosed:
Nov 19, 2024

CVE-2024-10708 on NVD →

System Dashboard [system-dashboard] < 2.8.10

unknown

[en] The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks

Affected:
up to 2.8.10
Fixed in:
2.8.10
Disclosed:
Mar 20, 2024

CVE-2023-7246 on NVD →

System Dashboard <= 2.8.9 - Reflected Cross-Site Scripting via X-Forwarded-For

medium

The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'X-Forwarded-For' header in all versions up to, and including, 2.8.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 2.8.9
Fixed in:
2.8.10
Disclosed:
Feb 28, 2024

CVE-2023-7246 on NVD →

System Dashboard [system-dashboard] < 2.8.8

unknown

[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and abov...

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Dec 7, 2023

CVE-2023-5712 on NVD →

System Dashboard [system-dashboard] < 2.8.8

unknown

[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and abov...

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Dec 7, 2023

CVE-2023-5713 on NVD →

System Dashboard [system-dashboard] < 2.8.8

unknown

[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,...

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Dec 7, 2023

CVE-2023-5710 on NVD →

System Dashboard [system-dashboard] < 2.8.8

unknown

[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, t...

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Dec 7, 2023

CVE-2023-5714 on NVD →

System Dashboard [system-dashboard] < 2.8.8

unknown

[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, t...

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Dec 7, 2023

CVE-2023-5711 on NVD →

System Dashboard <= 2.8.8 - Missing Authorization to Information Disclosure (sd_php_info)

medium

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to ret...

CVSS:
4.3
Affected:
up to 2.8.7
Fixed in:
2.8.8
Disclosed:
Dec 6, 2023

CVE-2023-5711 on NVD →

System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_constants)

medium

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to re...

CVSS:
4.3
Affected:
up to 2.8.7
Fixed in:
2.8.8
Disclosed:
Dec 6, 2023

CVE-2023-5710 on NVD →

System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_option_value)

medium

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to...

CVSS:
4.3
Affected:
up to 2.8.7
Fixed in:
2.8.8
Disclosed:
Dec 6, 2023

CVE-2023-5713 on NVD →

System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_global_value)

medium

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to...

CVSS:
4.3
Affected:
up to 2.8.7
Fixed in:
2.8.8
Disclosed:
Dec 6, 2023

CVE-2023-5712 on NVD →

System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_db_specs)

medium

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to ret...

CVSS:
4.3
Affected:
up to 2.8.7
Fixed in:
2.8.8
Disclosed:
Dec 6, 2023

CVE-2023-5714 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database