Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 741-760 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-24571 - Before 1 Plugin

The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues

PLUGIN Before 1

CVE-2021-24571

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24531 - Before 1 Plugin

The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.

PLUGIN Before 1

CVE-2021-24531

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24529 - Before 1 Plugin

The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.

PLUGIN Before 1

CVE-2021-24529

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24541 - Before 1 Plugin

The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.

PLUGIN Before 1

CVE-2021-24541

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24540 - Before 1 Plugin

The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.

PLUGIN Before 1

CVE-2021-24540

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24526 - Before 1 Plugin

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24526

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24363 - Before 1 Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images/SVG anywhere in the filesystem via a path traversal vector

PLUGIN Before 1

CVE-2021-24363

MEDIUM CVSS 4.9 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24519 - Before 1 Plugin

The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS payload in it, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24519

MEDIUM CVSS 4.8 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24362 - Before 1 Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issue

PLUGIN Before 1

CVE-2021-24362

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24495 - Before 1 Plugin

The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-24495

MEDIUM CVSS 6.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24505 - Before 1 Plugin

The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issues. The plugin was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the Forms "Add new" field.

PLUGIN Before 1

CVE-2021-24505

MEDIUM CVSS 5.4 2021-08-09
Threat Entry Updated 2025-05-07

CVE-2021-24502 - Before 1 Plugin

The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24502

MEDIUM CVSS 4.8 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24498 - Before 1 Plugin

The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-24498

MEDIUM CVSS 6.1 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24496 - Before 1 Plugin

The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

PLUGIN Before 1

CVE-2021-24496

MEDIUM CVSS 6.1 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24461 - Before 1 Plugin

The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Before 1

CVE-2021-24461

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24459 - Before 1 Plugin

The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Before 1

CVE-2021-24459

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24457 - Before 1 Plugin

The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Portfolio Responsive Gallery WordPress plugin before 1.1.8 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Before 1

CVE-2021-24457

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24455 - Before 1 Plugin

The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by users as low as Tutor Instructor. This lead to a Stored Cross-Site Scripting issue, which is triggered when viewing the Announcements list, and could result in privilege escalation when viewed by an admin.

PLUGIN Before 1

CVE-2021-24455

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24443 - Before 1 Plugin

The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile. This could allow a low privilege user to gain unauthorised access to the admin side of the blog by targeting an admin, inducing them to view their profile with a malicious payload adding a rogue account for example.

PLUGIN Before 1

CVE-2021-24443

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24447 - Before 1 Plugin

The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard

PLUGIN Before 1

CVE-2021-24447

MEDIUM CVSS 5.3 2021-07-19
Scroll to top