Known Vulnerabilities for products from Buymeacoffee
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Buymeacoffee".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-25030 json | Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7. | Not Provided | 2024-06-12 | 2026-04-28 |
| CVE-2023-2578 json | The Buy Me a Coffee WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high pri... | 4.8 - MEDIUM | 2023-07-10 | 2023-11-07 |
| CVE-2023-2082 json | The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in versions up ... | Not Provided | 2023-07-14 | 2026-04-08 |
| CVE-2023-2079 json | The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due to mi... | Not Provided | 2023-07-11 | 2026-04-08 |
| CVE-2023-2078 json | The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data du... | Not Provided | 2023-07-11 | 2026-04-08 |