← All credits
Pedro Paniago
12 vulnerability records and advisories credit this contributor.
CVE-2024-9944
WooCommerce <= 9.0.2 - Unauthenticated HTML Injection
CVE-2024-1463
LearnPress <= 4.2.6.3 - Authenticated(LP Instructor+) Stored Cross-Site Scripting
CVE-2024-1289
LearnPress <= 4.2.6.3 - Insecure Direct Object Reference
CVE-2024-1133
Tutor LMS <= 2.6.0 - Missing Authorization
CVE-2024-1128
Tutor LMS <= 2.6.0 - Authenticated(Student+) HTML Injection via Q&A
CVE-2024-0386
weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Referer
CVE-2023-7063
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthent
CVE-2023-6957
Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2023-6953
PDF Generator For Fluent Forms <= 1.1.7 - Cross-Site Scripting
CVE-2023-6842
Formidable Forms <= 6.7 - Authenticated (Administrator+) Stored Cross-Site Scripting