Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3361-3380 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2021-24830 - Changeset Plugin

The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2021-24830

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-42363 - Changeset Plugin

The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.6.8.

PLUGIN Changeset

CVE-2021-42363

MEDIUM CVSS 6.1 2021-11-19
Threat Entry Updated 2024-11-21

CVE-2021-42362 - Changeset Plugin

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.

PLUGIN Changeset

CVE-2021-42362

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24834 - Changeset Plugin

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of custom label parameters - vote button label , results link label and back to vote caption label.

PLUGIN Changeset

CVE-2021-24834

MEDIUM CVSS 5.4 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24833 - Changeset Plugin

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of question and answer text parameters in Create Poll module.

PLUGIN Changeset

CVE-2021-24833

MEDIUM CVSS 5.4 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24851 - Changeset Plugin

The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.

PLUGIN Changeset

CVE-2021-24851

MEDIUM CVSS 4.3 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24772 - Changeset Plugin

The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.

PLUGIN Changeset

CVE-2021-24772

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24598 - Changeset Plugin

The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2021-24598

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24827 - Changeset Plugin

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

PLUGIN Changeset

CVE-2021-24827

CRITICAL CVSS 9.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24844 - Changeset Plugin

The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue

PLUGIN Changeset

CVE-2021-24844

HIGH CVSS 7.2 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24710 - Changeset Plugin

The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Changeset

CVE-2021-24710

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24616 - Changeset Plugin

The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Changeset

CVE-2021-24616

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24594 - Changeset Plugin

The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Changeset

CVE-2021-24594

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-39346 - Changeset Plugin

The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Changeset

CVE-2021-39346

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24809 - Changeset Plugin

The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actions

PLUGIN Changeset

CVE-2021-24809

HIGH CVSS 8.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24808 - Changeset Plugin

The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2021-24808

MEDIUM CVSS 6.1 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24813 - Changeset Plugin

The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2021-24813

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24781 - Changeset Plugin

The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit)

PLUGIN Changeset

CVE-2021-24781

MEDIUM CVSS 4.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24570 - Changeset Plugin

The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.

PLUGIN Changeset

CVE-2021-24570

MEDIUM CVSS 4.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24885 - Changeset Plugin

The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-24885

MEDIUM CVSS 6.1 2021-10-25
Scroll to top