Skip to main content

Vendor/product archive

donations_project / donations CVEs

Beta · best-effort

3 CVEs tagged to donations_project / donations1 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-29433

Published May 13, 2022

Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0782

Published Apr 25, 2022

The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_val…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15772

Published Aug 29, 2019

The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1