Qriouslad System Dashboard vulnerabilities

7 known vulnerabilities affecting qriouslad/system_dashboard.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2025-10377MEDIUMCVSS 4.3≤ 2.8.202025-09-26
CVE-2025-10377 [MEDIUM] CWE-352 CVE-2025-10377: The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.20. This is due to missing nonce validation on the sd_toggle_logs() function. This makes it possible for unauthenticated attackers to toggle critical logging settings including Page Access Logs, Error Logs, and Email Delive
cvelistv5nvd
CVE-2024-12299MEDIUMCVSS 6.1≤ 2.8.172025-01-30
CVE-2024-12299 [MEDIUM] CWE-79 CVE-2024-12299: The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Fi The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull
cvelistv5nvd
CVE-2023-5712MEDIUMCVSS 4.3≤ 2.8.72023-12-07
CVE-2023-5712 [MEDIUM] CWE-862 CVE-2023-5712: The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a miss The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive global value
cvelistv5nvd
CVE-2023-5714MEDIUMCVSS 4.3≤ 2.8.72023-12-07
CVE-2023-5714 [MEDIUM] CWE-862 CVE-2023-5714: The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a miss The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve data key specs.
cvelistv5nvd
CVE-2023-5713MEDIUMCVSS 4.3≤ 2.8.72023-12-07
CVE-2023-5713 [MEDIUM] CWE-862 CVE-2023-5713: The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a miss The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve potentially sensitive o
cvelistv5nvd
CVE-2023-5710MEDIUMCVSS 4.3≤ 2.8.72023-12-07
CVE-2023-5710 [MEDIUM] CWE-862 CVE-2023-5710: The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a miss The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information such
cvelistv5nvd
CVE-2023-5711MEDIUMCVSS 4.3≤ 2.8.72023-12-07
CVE-2023-5711 [MEDIUM] CWE-862 CVE-2023-5711: The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a miss The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information provi
cvelistv5nvd