Known Vulnerabilities for products from Webidsupport
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Webidsupport".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-47397 json | WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php. | 9.8 - CRITICAL | 2023-11-08 | 2023-11-15 |
| CVE-2022-41477 json | A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php f... | 9.1 - CRITICAL | 2022-10-14 | 2022-10-20 |
| CVE-2020-23359 json | WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to... | 9.8 - CRITICAL | 2021-01-27 | 2021-02-02 |
| CVE-2019-11592 json | WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory... | 6.1 - MEDIUM | 2019-04-29 | 2019-04-29 |
| CVE-2018-1000882 json | WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arb... | 7.5 - HIGH | 2018-12-20 | 2019-01-07 |
| CVE-2018-1000868 json | WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php... | 6.1 - MEDIUM | 2018-12-20 | 2019-01-07 |
| CVE-2018-1000867 json | WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that c... | 8.8 - HIGH | 2018-12-20 | 2019-01-07 |
| CVE-2014-5114 json | WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter. | Not Provided | 2014-07-29 | 2026-05-06 |
| CVE-2014-5101 json | Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or H... | Not Provided | 2014-07-25 | 2026-05-06 |
| CVE-2011-3815 json | WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in... | Not Provided | 2011-09-24 | 2026-04-29 |
| CVE-2010-4873 json | Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web scr... | Not Provided | 2011-10-07 | 2026-04-29 |
| CVE-2008-7119 json | SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL comman... | Not Provided | 2009-08-28 | 2026-04-23 |
| CVE-2008-7118 json | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows rem... | Not Provided | 2009-08-28 | 2026-04-23 |
| CVE-2008-7117 json | eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via... | Not Provided | 2009-08-28 | 2026-04-23 |
| CVE-2008-7116 json | SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbi... | Not Provided | 2009-08-28 | 2026-04-23 |
Known software with vulnerabilities from Webidsupport
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Webidsupport | Webid | 1.0.3 |