WP Symposium [wp-symposium] < 15.9 (closed)
unknown
[en] The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.
- Affected:
- up to 15.9
- Fixed in:
- 15.9
- Disclosed:
- Sep 25, 2019
CVE-2015-9414 on NVD →
WP Symposium <= 15.8.1 - Reflected Cross-Site Scripting
medium
The WP Symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.
- CVSS:
- 6.1
- Affected:
- up to 15.8.1
- Fixed in:
- 15.9
- Disclosed:
- Sep 6, 2015
CVE-2015-9414 on NVD →
WP Symposium [wp-symposium] < 15.8 (closed)
unknown
[en] SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the size parameter to get_album_item.php.
- Affected:
- up to 15.8
- Fixed in:
- 15.8
- Disclosed:
- Aug 19, 2015
CVE-2015-6522 on NVD →
WP Symposium [wp-symposium] < 15.2 (closed)
unknown
Because of this vulnerability an attacker can extract information from the database.
Upgrade to version 15.8.
- Affected:
- up to 15.2
- Fixed in:
- 15.2
- Disclosed:
- Aug 18, 2015
WP Symposium < 15.8 - Blind SQL Injection
high
The WP Symposium plugin for WordPress is vulnerable to blind SQL Injection in versions before 15.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already...
- CVSS:
- 7.2
- Affected:
- up to 15.8
- Fixed in:
- 15.8
- Disclosed:
- Aug 10, 2015
WP Symposium [wp-symposium] < 15.8
unknown
The WP Symposium plugin for WordPress is vulnerable to blind SQL Injection in versions before 15.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already...
- Affected:
- up to 15.8
- Fixed in:
- 15.8
- Disclosed:
- Aug 10, 2015
WP Symposium <= 15.8 - Unauthenticated SQL Injection
critical
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the size parameter to get_album_item.php.
- CVSS:
- 9.8
- Affected:
- up to 15.8
- Fixed in:
- 15.8
- Disclosed:
- Aug 9, 2015
CVE-2015-6522 on NVD →
WP Symposium [wp-symposium] < 15.4 (closed)
unknown
This WordPress Symposium plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Related records:
http://db.threatpress.com/vulnerability/symposium-/wordpress-wp-symposium-plugi...
- Affected:
- up to 15.4
- Fixed in:
- 15.4
- Disclosed:
- May 21, 2015
WP Symposium [wp-symposium] < 15.4 (closed)
unknown
[en] SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.
- Affected:
- up to 15.4
- Fixed in:
- 15.4
- Disclosed:
- May 15, 2015
CVE-2015-3325 on NVD →
WP Symposium < 15.4 - SQL Injection
medium
SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.
- CVSS:
- 5.3
- Affected:
- up to 15.4
- Fixed in:
- 15.4
- Disclosed:
- Apr 14, 2015
CVE-2015-3325 on NVD →
WP Symposium [wp-symposium] < 15.1
unknown
[en] Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in server/php/.
- Affected:
- up to 15.1
- Fixed in:
- 15.1
- Disclosed:
- Jan 13, 2015
CVE-2014-10021 on NVD →
WP Symposium [wp-symposium] < 14.11 (closed)
unknown
[en] SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.
- Affected:
- up to 14.11
- Fixed in:
- 14.11
- Disclosed:
- Dec 24, 2014
CVE-2014-8810 on NVD →
WP Symposium [wp-symposium] < 14.11 (closed)
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the WP Symposium plugin before 14.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter in an addComment action to ajax/profile_functions.php, (2) compose_text parameter in a sendMail action to ajax/mail_func...
- Affected:
- up to 14.11
- Fixed in:
- 14.11
- Disclosed:
- Dec 24, 2014
CVE-2014-8809 on NVD →
WP Symposium <= 14.11 - Arbitrary File Upload
critical
The WP Symposium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the UploadHandler.php file in versions up to, and including, 14.11. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possib...
- CVSS:
- 9.8
- Affected:
- up to 14.11
- Fixed in:
- 15.1
- Disclosed:
- Dec 11, 2014
CVE-2014-10021 on NVD →
WP Symposium < 14.11 - Authenticated SQL Injection
critical
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.
- CVSS:
- 9.9
- Affected:
- up to 14.11
- Fixed in:
- 14.11
- Disclosed:
- Nov 26, 2014
CVE-2014-8810 on NVD →
WP Symposium <= 14.10 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the WP Symposium plugin before 14.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter in an addComment action to ajax/profile_functions.php, (2) compose_text parameter in a sendMail action to ajax/mail_functions...
- CVSS:
- 6.1
- Affected:
- up to 14.10
- Fixed in:
- 14.11
- Disclosed:
- Nov 26, 2014
CVE-2014-8809 on NVD →
WP Symposium <= 12.11 - SQL Injections
critical
The WP Symposium plugin for WordPress is vulnerable to various SQL Injections in versions up to, and including, 12.09 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...
- CVSS:
- 9.8
- Affected:
- up to 12.11
- Fixed in:
- 12.12
- Disclosed:
- Aug 1, 2014
WP Symposium < 13.04 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in invite.php in the WP Symposium plugin before 13.04 for WordPress allows remote attackers to inject arbitrary web script or HTML via the u parameter.
- CVSS:
- 7.1
- Affected:
- up to 13.04
- Fixed in:
- 13.04
- Disclosed:
- Aug 1, 2014
CVE-2013-2695 on NVD →
WP Symposium <= 13.04 - Open Redirection
medium
Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the u parameter.
- CVSS:
- 6.1
- Affected:
- up to 13.04
- Fixed in:
- 13.05
- Disclosed:
- Aug 1, 2014
CVE-2013-2694 on NVD →
WP Symposium <= 11.11.26 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.
- CVSS:
- 6.1
- Affected:
- up to 11.11.26
- Fixed in:
- 11.12.08
- Disclosed:
- Aug 1, 2014
CVE-2011-3841 on NVD →
WP Symposium [wp-symposium] < 12.12 (closed)
unknown
The WP Symposium plugin for WordPress is vulnerable to various SQL Injections in versions up to, and including, 12.09 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...
- Affected:
- up to 12.12
- Fixed in:
- 12.12
- Disclosed:
- Aug 1, 2014
WP Symposium [wp-symposium] < 13.05 (closed)
unknown
[en] Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the u parameter.
- Affected:
- up to 13.05
- Fixed in:
- 13.05
- Disclosed:
- Mar 28, 2014
CVE-2013-2694 on NVD →
WP Symposium [wp-symposium] < 13.04 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in invite.php in the WP Symposium plugin before 13.04 for WordPress allows remote attackers to inject arbitrary web script or HTML via the u parameter.
- Affected:
- up to 13.04
- Fixed in:
- 13.04
- Disclosed:
- Mar 28, 2014
CVE-2013-2695 on NVD →
WP Symposium [wp-symposium] < 11.12.24 (closed)
unknown
[en] Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via...
- Affected:
- up to 11.12.24
- Fixed in:
- 11.12.24
- Disclosed:
- Jan 4, 2012
CVE-2011-5051 on NVD →
WP Symposium < 11.12.24 - Arbitrary File Upload
high
Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via a dir...
- CVSS:
- 8.8
- Affected:
- up to 11.12.24
- Fixed in:
- 11.12.24
- Disclosed:
- Dec 28, 2011
CVE-2011-5051 on NVD →
WP Symposium [wp-symposium] < 11.12.08 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.
- Affected:
- up to 11.12.08
- Fixed in:
- 11.12.08
- Disclosed:
- Dec 27, 2011
CVE-2011-3841 on NVD →
WP Symposium [wp-symposium] < 0.65 (closed)
unknown
This WordPress Symposium plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 0.65
- Fixed in:
- 0.65
- Disclosed:
- Aug 17, 2011
WP Symposium [wp-symposium] < 15.8 (closed)
unknown
The wp-symposium WordPress plugin was affected by a Blind SQL Injection security vulnerability.
- Affected:
- up to 15.8
- Fixed in:
- 15.8
WP Symposium [wp-symposium] < 11.08.18 (closed)
unknown
The wp-symposium WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 11.08.18
- Fixed in:
- 11.08.18
WP Symposium [wp-symposium] < 12.07.01 (closed)
unknown
The wp-symposium WordPress plugin was affected by a Multiple SQL Injections security vulnerability.
- Affected:
- up to 12.07.01
- Fixed in:
- 12.07.01
WP Symposium [wp-symposium] <= 12.07.07 (unfixed + closed)
unknown
The wp-symposium WordPress plugin was affected by an Authentication Bypass security vulnerability.
- Affected:
- up to 12.07.07
- Fix:
- No patched version reported
WP Symposium [wp-symposium] < 12.12 (closed)
unknown
The wp-symposium WordPress plugin was affected by a Multiple SQL Injections security vulnerability.
- Affected:
- up to 12.12
- Fixed in:
- 12.12
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database