ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-50843
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Clockwork Clockwork SMS Notfications.This issue affects Cl

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Clockwork Clockwork SMS Notfications.This issue affects Clockwork SMS Notfications: from n/a through 3.0.4.

NVD description · AI analysis pending
7.2<1%
  • mediaburst clockwork sms notfications
CVE-2023-2701
The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting w

The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

NVD description · AI analysis pending
6.1<1% PoC
  • mediaburst gravity forms
CVE-2017-18555
The booking-sms plugin before 1.1.0 for WordPress has XSS.

The booking-sms plugin before 1.1.0 for WordPress has XSS.

NVD description · AI analysis pending
6.1<1%
  • mediaburst booking calendar
CVE-2017-18495
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.

The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.

NVD description · AI analysis pending
6.1<1%
  • mediaburst gravity forms
CVE-2017-18489
The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.

The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.

NVD description · AI analysis pending
6.1<1%
  • mediaburst contact form 7 - clockwork sms
CVE-2017-17780
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php.

The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar - Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2, Gravity Forms - Clockwork SMS 2.2, and WP e-Commerce - Clockwork SMS 2.0.5.

NVD description · AI analysis pending
6.1<1% PoC
  • mediaburst booking calendar sms
  • mediaburst clockwork sms notfications
  • mediaburst contact form 7 sms
  • +1 more