Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total45
Critical1
High7
Medium36
Reset
Showing 41-45 of 45 records
Threat Entry Updated 2024-11-21

CVE-2021-24847 - Before 8 Plugin

The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed

PLUGIN Before 8

CVE-2021-24847

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24506 - Before 8 Plugin

The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.

PLUGIN Before 8

CVE-2021-24506

HIGH CVSS 8.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24371 - Before 8 Plugin

The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could use that feature to scan the internal network via a SSRF attack.

PLUGIN Before 8

CVE-2021-24371

LOW CVSS 2.7 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24383 - Before 8 Plugin

The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Before 8

CVE-2021-24383

MEDIUM CVSS 5.4 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24342 - Before 8 Theme

The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.

THEME Before 8

CVE-2021-24342

MEDIUM CVSS 6.1 2021-06-07
Scroll to top