System Dashboard <= 2.8.20 - Cross-Site Request Forgery
medium
The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.20. This is due to missing nonce validation on the sd_toggle_logs() function. This makes it possible for unauthenticated attackers to toggle critical logging settings including Page Access Log...
- CVSS:
- 4.3
- Affected:
- up to 2.8.20
- Fixed in:
- 2.8.21
- Disclosed:
- Sep 25, 2025
CVE-2025-10377 on NVD →
System Dashboard [system-dashboard] < 2.8.19
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects System Dashboard: from n/a through 2.8.18.
- Affected:
- up to 2.8.19
- Fixed in:
- 2.8.19
- Disclosed:
- Feb 25, 2025
CVE-2025-26911 on NVD →
System Dashboard <= 2.8.18 - Authenticated (Subscriber+) Sensitive Information Exposure
medium
The System Dashboard plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 2.8.18
- Fixed in:
- 2.8.19
- Disclosed:
- Feb 23, 2025
CVE-2025-26911 on NVD →
System Dashboard <= 2.8.17 - Reflected Cross-Site Scripting via Filename Parameter
medium
The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 2.8.17
- Fixed in:
- 2.8.18
- Disclosed:
- Jan 30, 2025
CVE-2024-12299 on NVD →
System Dashboard [system-dashboard] < 2.8.18
unknown
[en] The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 2.8.18
- Fixed in:
- 2.8.18
- Disclosed:
- Jan 30, 2025
CVE-2024-12299 on NVD →
System Dashboard [system-dashboard] < 2.8.15
unknown
[en] The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server
- Affected:
- up to 2.8.15
- Fixed in:
- 2.8.15
- Disclosed:
- Dec 10, 2024
CVE-2024-10708 on NVD →
System Dashboard [system-dashboard] < 2.8.15
unknown
[en] The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
- Affected:
- up to 2.8.15
- Fixed in:
- 2.8.15
- Disclosed:
- Dec 10, 2024
CVE-2024-11107 on NVD →
System Dashboard <= 2.8.14 - Unauthenticated Stored Cross-Site Scripting
high
The System Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- CVSS:
- 7.2
- Affected:
- up to 2.8.14
- Fixed in:
- 2.8.15
- Disclosed:
- Nov 19, 2024
CVE-2024-11107 on NVD →
System Dashboard <= 2.8.14 - Authenticated (Admin+) Arbitrary File Read
medium
The System Dashboard plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.14 via the 'sd_viewer' action. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain...
- CVSS:
- 4.9
- Affected:
- up to 2.8.14
- Fixed in:
- 2.8.15
- Disclosed:
- Nov 19, 2024
CVE-2024-10708 on NVD →
System Dashboard [system-dashboard] < 2.8.10
unknown
[en] The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks
- Affected:
- up to 2.8.10
- Fixed in:
- 2.8.10
- Disclosed:
- Mar 20, 2024
CVE-2023-7246 on NVD →
System Dashboard <= 2.8.9 - Reflected Cross-Site Scripting via X-Forwarded-For
medium
The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'X-Forwarded-For' header in all versions up to, and including, 2.8.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 2.8.9
- Fixed in:
- 2.8.10
- Disclosed:
- Feb 28, 2024
CVE-2023-7246 on NVD →
System Dashboard [system-dashboard] < 2.8.8
unknown
[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and abov...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 7, 2023
CVE-2023-5712 on NVD →
System Dashboard [system-dashboard] < 2.8.8
unknown
[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and abov...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 7, 2023
CVE-2023-5713 on NVD →
System Dashboard [system-dashboard] < 2.8.8
unknown
[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 7, 2023
CVE-2023-5710 on NVD →
System Dashboard [system-dashboard] < 2.8.8
unknown
[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, t...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 7, 2023
CVE-2023-5714 on NVD →
System Dashboard [system-dashboard] < 2.8.8
unknown
[en] The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, t...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 7, 2023
CVE-2023-5711 on NVD →
System Dashboard <= 2.8.8 - Missing Authorization to Information Disclosure (sd_php_info)
medium
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to ret...
- CVSS:
- 4.3
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 6, 2023
CVE-2023-5711 on NVD →
System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_constants)
medium
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to re...
- CVSS:
- 4.3
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 6, 2023
CVE-2023-5710 on NVD →
System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_option_value)
medium
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to...
- CVSS:
- 4.3
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 6, 2023
CVE-2023-5713 on NVD →
System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_global_value)
medium
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to...
- CVSS:
- 4.3
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 6, 2023
CVE-2023-5712 on NVD →
System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_db_specs)
medium
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to ret...
- CVSS:
- 4.3
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- Dec 6, 2023
CVE-2023-5714 on NVD →
System Dashboard [system-dashboard] < 2.8.21
unknown
- Affected:
- up to 2.8.21
- Fixed in:
- 2.8.21
CVE-2025-10377 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database