Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total50
Critical2
High8
Medium39
Reset
Showing 41-50 of 50 records
Threat Entry Updated 2024-11-21

CVE-2022-1239 - Before 8 Plugin

The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks

PLUGIN Before 8

CVE-2022-1239

HIGH CVSS 8.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0429 - Before 8 Plugin

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

PLUGIN Before 8

CVE-2022-0429

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2026-03-20

CVE-2021-25115 - Before 8 Plugin

The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.

PLUGIN Before 8

CVE-2021-25115

MEDIUM CVSS 6.4 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25040 - Before 8 Plugin

The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 8

CVE-2021-25040

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24705 - Before 8 Plugin

The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape some of its settings as well as form fields before outputting them in attributes. This could allow attackers to make a logged in admin edit arbitrary forms with Cross-Site Scripting payloads in them

PLUGIN Before 8

CVE-2021-24705

MEDIUM CVSS 4.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24847 - Before 8 Plugin

The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed

PLUGIN Before 8

CVE-2021-24847

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24506 - Before 8 Plugin

The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.

PLUGIN Before 8

CVE-2021-24506

HIGH CVSS 8.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24371 - Before 8 Plugin

The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could use that feature to scan the internal network via a SSRF attack.

PLUGIN Before 8

CVE-2021-24371

LOW CVSS 2.7 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24383 - Before 8 Plugin

The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Before 8

CVE-2021-24383

MEDIUM CVSS 5.4 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24342 - Before 8 Theme

The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.

THEME Before 8

CVE-2021-24342

MEDIUM CVSS 6.1 2021-06-07
Scroll to top