VendorsTMS-Outsourceameliaall versions
Vulnerabilities

TMS-Outsource Amelia

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2024-22298
WordPress Amelia plugin <= 1.0.98 - Broken Access Control vulnerability
Published 2024-06-10 · Analyzed
9.8EPSS 0.004
CVE-2022-0687
Amelia < 1.0.46 - Manager+ RCE
Published 2022-03-21 · Modified
8.8EPSS 0.015
CVE-2023-29427
WordPress Amelia Plugin <= 1.0.75 is vulnerable to Cross Site Scripting (XSS)
Published 2023-06-26 · Modified
7.1EPSS 0.004
CVE-2023-50860
WordPress Amelia Plugin <= 1.0.85 is vulnerable to Cross Site Scripting (XSS)
Published 2023-12-28 · Modified
6.5EPSS 0.003
CVE-2023-6808
Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
Published 2024-02-05 · Modified
6.4EPSS 0.005
CVE-2022-0627
Amelia < 1.0.46 - Reflected Cross-Site Scripting
Published 2022-03-21 · Modified
6.1EPSS 0.008
CVE-2023-27918
Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthenticated attacker to inject an arbitrary script by having a user who is logging in the WordPress where the product is installed visit a malicious URL.
Published 2023-05-10 · Modified
6.1EPSS 0.005
CVE-2022-0825
Amelia < 1.0.49 - Customer+ Arbitrary Appointments Status Update
Published 2022-04-04 · Modified
5.5EPSS 0.008
CVE-2022-0720
Amelia < 1.0.47 - Customer+ Arbitrary Appointments Update and Sensitive Data Disclosure
Published 2022-03-28 · Modified
5.5EPSS 0.006
CVE-2022-0837
Amelia < 1.0.48 - Customer+ SMS Service Abuse and Sensitive Data Disclosure
Published 2022-04-04 · Modified
5.5EPSS 0.006
CVE-2024-6225
Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Published 2024-06-21 · Modified
4.8EPSS 0.003
CVE-2022-0616
Amelia < 1.0.46 - Arbitrary Customer Deletion via CSRF
Published 2022-03-21 · Modified
4.3EPSS 0.004