cbcvebase.

Ruben Garcia Gamipress vulnerabilities

7 known vulnerabilities affecting ruben_garcia/gamipress.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-59538P2CRITICALCVSS 9.3≥ n/a, ≤ 7.9.72026-07-27
CVE-2026-59538 [CRITICAL] CWE-89 CVE-2026-59538: Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
nvd
CVE-2026-94177P2HIGHCVSS 8.5≥ n/a, ≤ 8.0.22026-09-30
CVE-2026-94177 [HIGH] CWE-89 CVE-2026-94177: Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions. Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
nvd
CVE-2026-48874P3HIGHCVSS 8.5≥ n/a, ≤ 7.8.72026-06-15
CVE-2026-48874 [HIGH] CWE-89 CVE-2026-48874: Subscriber SQL Injection in GamiPress <= 7.8.7 versions. Subscriber SQL Injection in GamiPress <= 7.8.7 versions.
nvd
CVE-2025-47508P3HIGHCVSS 7.5≤ 7.3.72025-05-07
CVE-2025-47508 [HIGH] CWE-98 CVE-2025-47508: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ruben Garcia GamiPress gamipress allows PHP Local File Inclusion.This issue affects GamiPress: from n/a through <= 7.3.7.
nvd
CVE-2025-49326P3HIGHCVSS 7.6≤ 7.4.52025-06-06
CVE-2025-49326 [HIGH] CWE-89 CVE-2025-49326: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through <= 7.4.5.
nvd
CVE-2026-24546P4MEDIUMCVSS 5.3≥ n/a, ≤ 7.6.32026-05-25
CVE-2026-24546 [MEDIUM] CWE-862 CVE-2026-24546: Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configur Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3.
cvelistv5nvd
CVE-2026-32420P4MEDIUMCVSS 5.4≤ 7.6.62026-03-13
CVE-2026-32420 [MEDIUM] CWE-352 CVE-2026-32420: Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Sit Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forgery.This issue affects GamiPress: from n/a through <= 7.6.6.
nvd
Ruben Garcia Gamipress vulnerabilities | cvebase