Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 721-740 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-24676 - Before 1 Plugin

The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24676

MEDIUM CVSS 6.1 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24673 - Before 1 Plugin

The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24673

MEDIUM CVSS 4.8 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24643 - Before 1 Plugin

The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2021-24643

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24633 - Before 1 Plugin

The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

PLUGIN Before 1

CVE-2021-24633

MEDIUM CVSS 4.3 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24618 - Before 1 Plugin

The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.

PLUGIN Before 1

CVE-2021-24618

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24613 - Before 1 Plugin

The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24613

MEDIUM CVSS 4.8 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24606 - Before 1 Plugin

The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+

PLUGIN Before 1

CVE-2021-24606

HIGH CVSS 8.8 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24587 - Before 1 Plugin

The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-24587

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24582 - Before 1 Plugin

The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it its settings page, leading to a Stored Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-24582

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24604 - Before 1 Plugin

The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 1

CVE-2021-24604

MEDIUM CVSS 4.8 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24623 - Before 1 Plugin

The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape form values before saving to the database or when outputting, which allows high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24623

MEDIUM CVSS 4.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24614 - Before 1 Plugin

The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24614

MEDIUM CVSS 4.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24586 - Before 1 Plugin

The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned by the plugin), this could lead to Stored XSS issue which will be triggered either in the backend, frontend or both depending on the payload used.

PLUGIN Before 1

CVE-2021-24586

MEDIUM CVSS 4.3 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24510 - Before 1 Plugin

The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24510

MEDIUM CVSS 6.1 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24590 - Before 1 Plugin

The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options.

PLUGIN Before 1

CVE-2021-24590

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24568 - Before 1 Plugin

The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24568

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24513 - Before 1 Plugin

The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24513

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24303 - Before 1 Plugin

The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues

PLUGIN Before 1

CVE-2021-24303

HIGH CVSS 8.8 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24665 - Before 1 Plugin

The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2021-24665

MEDIUM CVSS 5.4 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24602 - Before 1 Plugin

The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page

PLUGIN Before 1

CVE-2021-24602

HIGH CVSS 8.8 2021-08-23
Scroll to top