Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total27
Critical1
High5
Medium21
Reset
Showing 21-27 of 27 records
Threat Entry Updated 2025-02-25

CVE-2023-0937 - Before 9 Plugin

The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

PLUGIN Before 9

CVE-2023-0937

MEDIUM CVSS 6.1 2023-03-20
Threat Entry Updated 2025-03-10

CVE-2023-0230 - Before 9 Plugin

The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 9

CVE-2023-0230

MEDIUM CVSS 5.4 2023-02-27
Threat Entry Updated 2024-11-21

CVE-2022-0594 - Before 9 Plugin

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

PLUGIN Before 9

CVE-2022-0594

MEDIUM CVSS 5.3 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-1967 - Before 9 Plugin

The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update the plugin's settings. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

PLUGIN Before 9

CVE-2022-1967

MEDIUM CVSS 6.5 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2022-0784 - Before 9 Plugin

The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

PLUGIN Before 9

CVE-2022-0784

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-25031 - Before 9 Plugin

The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 9

CVE-2021-25031

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24374 - Before 9 Plugin

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.

PLUGIN Before 9

CVE-2021-24374

MEDIUM CVSS 5.3 2021-06-21
Scroll to top