Skip to main content

Vendor archive

bestwebsoft CVEs

Beta · best-effort

75 CVEs tagged to vendor bestwebsoft3 Critical, 9 High, 55 Medium, 8 Low, 0 Unrated.

CVE-2024-13908

Published Mar 8, 2025

The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3112

Published Jul 12, 2024

The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to upload arbitrary fi…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35678

Published Jun 8, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft.This issue affects Contact Form…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2200

Published Apr 9, 2024

The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_subject’ parameter in all versions up to, and includ…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45771

Published Mar 26, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.This issue affects Contact For…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6821

Published Mar 18, 2024

The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6250

Published Dec 26, 2023

The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-10127

Published Dec 26, 2023

A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation lead…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-125109

Published Dec 26, 2023

A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.27. It has been declared as problematic. This vulnerability affects the function bws_add_menu_render of the file…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-10017

Published Dec 26, 2023

A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.04 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29096

Published Dec 20, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-36527

Published Nov 7, 2023

Improper Neutralization of Formula Elements in a CSV File vulnerability in BestWebSoft Post to CSV by BestWebSoft.This issue affects Post to CSV by BestWebSoft: from n/a through 1…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-36508

Published Oct 31, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4469

Published Oct 6, 2023

The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-28778

Published Jun 22, 2023

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Pagination plugin <= 1.2.2 versions.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-125103

Published May 31, 2023

A vulnerability was found in BestWebSoft Twitter Plugin up to 1.3.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function twttr_setting…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-10015

Published May 31, 2023

A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twttr_settings_page of the file tw…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-125102

Published May 29, 2023

A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unknown functionality of the comp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-125100

Published May 2, 2023

A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross si…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-0765

Published Apr 17, 2023

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must ha…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0764

Published Apr 17, 2023

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The a…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-44734

Published Apr 16, 2023

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 versions.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-125097

Published Apr 10, 2023

A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_settings_page of the file faceboo…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-10012

Published Apr 10, 2023

A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the function fcbk_bttn_plgn_settings…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-125095

Published Apr 9, 2023

A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function bws_add_menu_render of the fi…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 75 CVEsPage 1 of 3