Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total65
Critical5
High14
Medium44
Reset
Showing 61-65 of 65 records
Threat Entry Updated 2024-11-21

CVE-2021-24806 - Before 7 Plugin

The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.

PLUGIN Before 7

CVE-2021-24806

MEDIUM CVSS 4.3 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24691 - Before 7 Plugin

The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 7

CVE-2021-24691

MEDIUM CVSS 4.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24368 - Before 7 Plugin

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link

PLUGIN Before 7

CVE-2021-24368

MEDIUM CVSS 6.1 2021-06-20
Threat Entry Updated 2024-11-21

CVE-2021-24221 - Before 7 Plugin

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this shortcode in post or pages being author, such user could gain unauthorised access to the DBMS. If the shortcode (without the id attribute) is embed on a public page or post, then unauthenticated users could exploit the injection.

PLUGIN Before 7

CVE-2021-24221

HIGH CVSS 8.8 2021-04-12
Threat Entry Updated 2025-03-24

CVE-2021-24177 - Before 7 Plugin

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

PLUGIN Before 7

CVE-2021-24177

MEDIUM CVSS 5.4 2021-04-05
Scroll to top