Products: 2
Vulnerabilities: 6
Known Exploited: 0
0
Critical Level Threats
1
High Level Threats
4
Medium Level Threats
1
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-11898
White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings
Last Modified: Jul 11, 2026
Published: Jul 11, 2026
CVE-2024-4280
White Label CMS <= 2.7.3 - Missing Authorization to Plugin Settings Reset
Last Modified: Apr 15, 2026
Published: May 10, 2024
CVE-2022-4302
White Label CMS < 2.5 - Admin+ PHP Object Injection
Last Modified: Apr 10, 2025
Published: Jan 02, 2023
CVE-2022-0422
White Label MS < 2.2.9 - Reflected Cross-Site Scripting
Last Modified: Nov 21, 2024
Published: Mar 07, 2022
CVE-2012-5387
Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, as demonstrated by a developer name containing XSS sequences.
Last Modified: Apr 11, 2025
Published: Oct 24, 2012
Items Per Page
