Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 101-120 of 837 records
Threat Entry Updated 2025-06-11

CVE-2023-6030 - Before 1 Plugin

The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker

PLUGIN Before 1

CVE-2023-6030

MEDIUM CVSS 5.4 2025-05-15
Threat Entry Updated 2025-06-04

CVE-2023-5932 - Before 1 Plugin

The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-5932

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-06-11

CVE-2023-2334 - Before 1 Plugin

The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

PLUGIN Before 1

CVE-2023-2334

MEDIUM CVSS 5.4 2025-05-15
Threat Entry Updated 2025-05-28

CVE-2025-3514 - Before 1 Plugin

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2025-3514

LOW CVSS 3.5 2025-05-02
Threat Entry Updated 2025-05-28

CVE-2025-3513 - Before 1 Plugin

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2025-3513

LOW CVSS 3.5 2025-05-02
Threat Entry Updated 2025-05-09

CVE-2025-3471 - Before 1 Plugin

The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action

PLUGIN Before 1

CVE-2025-3471

MEDIUM CVSS 4.9 2025-04-30
Threat Entry Updated 2025-04-23

CVE-2024-10680 - Before 1 Plugin

The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-10680

MEDIUM CVSS 4.8 2025-04-16
Threat Entry Updated 2025-06-12

CVE-2025-2048 - Before 1 Plugin

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server

PLUGIN Before 1

CVE-2025-2048

MEDIUM CVSS 4.1 2025-04-01
Threat Entry Updated 2025-05-13

CVE-2025-0613 - Before 1 Plugin

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed

PLUGIN Before 1

CVE-2025-0613

MEDIUM CVSS 6.1 2025-03-31
Threat Entry Updated 2025-05-06

CVE-2024-12683 - Before 1 Plugin

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-12683

LOW CVSS 3.5 2025-03-26
Threat Entry Updated 2025-04-01

CVE-2024-13123 - Before 1 Plugin

The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-13123

LOW CVSS 3.5 2025-03-25
Threat Entry Updated 2025-04-01

CVE-2024-13122 - Before 1 Plugin

The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-13122

LOW CVSS 3.5 2025-03-25
Threat Entry Updated 2025-05-06

CVE-2024-12682 - Before 1 Plugin

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-12682

MEDIUM CVSS 6.1 2025-03-25
Threat Entry Updated 2025-04-01

CVE-2024-10566 - Before 1 Plugin

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-10566

MEDIUM CVSS 6.1 2025-03-25
Threat Entry Updated 2025-04-02

CVE-2024-10565 - Before 1 Plugin

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-10565

MEDIUM CVSS 6.1 2025-03-25
Threat Entry Updated 2025-04-29

CVE-2024-12109 - Before 1 Plugin

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

PLUGIN Before 1

CVE-2024-12109

MEDIUM CVSS 4.1 2025-03-25
Threat Entry Updated 2025-05-05

CVE-2024-10638 - Before 1 Plugin

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

PLUGIN Before 1

CVE-2024-10638

MEDIUM CVSS 4.1 2025-03-25
Threat Entry Updated 2025-04-03

CVE-2024-10560 - Before 1 Plugin

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-10560

LOW CVSS 3.5 2025-03-25
Threat Entry Updated 2025-05-13

CVE-2024-13124 - Before 1 Plugin

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-13124

LOW CVSS 3.5 2025-03-24
Threat Entry Updated 2025-05-13

CVE-2024-10558 - Before 1 Plugin

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-10558

LOW CVSS 3.5 2025-03-24
Scroll to top