Known Vulnerabilities for products from Tms-outsource

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Tms-outsource".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2024-6225 json The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting... Not Provided 2024-06-21 2026-04-08
CVE-2024-0591 json The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Reflect... Not Provided 2024-03-13 2026-04-08
CVE-2023-50860 json 5.4 - MEDIUM 2023-12-28 2024-01-04
CVE-2023-29427 json Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar – Amelia plu... 6.1 - MEDIUM 2023-06-26 2023-06-30
CVE-2023-27918 json Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 ... 6.1 - MEDIUM 2023-05-10 2023-05-17
CVE-2023-23876 json Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TMS-Plugins wpDataTables plugin <= 2.1.49 versions. 5.4 - MEDIUM 2023-05-03 2023-05-06
CVE-2023-6808 json The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting... Not Provided 2024-02-05 2026-04-08
CVE-2023-4314 json The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deserializing ... 7.2 - HIGH 2023-09-11 2023-11-07
CVE-2022-29432 json Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugi... 4.8 - MEDIUM 2022-05-20 2022-05-26
CVE-2022-25618 json Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2.1.27 4.8 - MEDIUM 2022-04-04 2022-04-11
CVE-2022-0837 json The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any c... 5.4 - MEDIUM 2022-04-04 2023-11-07
CVE-2022-0825 json The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any custome... 5.4 - MEDIUM 2022-04-04 2022-06-03
CVE-2022-0720 json The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any custome... 5.4 - MEDIUM 2022-03-28 2022-04-04
CVE-2022-0687 json The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, whi... 8.8 - HIGH 2022-03-21 2022-03-30
CVE-2022-0627 json The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an adm... 6.1 - MEDIUM 2022-03-21 2022-03-28
CVE-2022-0616 json The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attack... 4.3 - MEDIUM 2022-03-21 2022-03-28
CVE-2021-24200 json The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to... 6.5 - MEDIUM 2021-04-12 2021-04-13
CVE-2021-24199 json The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to... 6.5 - MEDIUM 2021-04-12 2021-04-13
CVE-2021-24198 json The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege... 8.1 - HIGH 2021-04-12 2022-07-30
CVE-2021-24197 json The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege... 8.1 - HIGH 2021-04-12 2022-07-30

Known software with vulnerabilities from Tms-outsource

Type Vendor Product Version
ApplicationTms-outsourceWpdatatables Lite1.0