Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3401-3408 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2021-24239 - Changeset Plugin

The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.

PLUGIN Changeset

CVE-2021-24239

MEDIUM CVSS 6.1 2021-04-22
Threat Entry Updated 2024-11-21

CVE-2021-24221 - Changeset Plugin

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this shortcode in post or pages being author, such user could gain unauthorised access to the DBMS. If the shortcode (without the id attribute) is embed on a public page or post, then unauthenticated users could exploit the injection.

PLUGIN Changeset

CVE-2021-24221

HIGH CVSS 8.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24225 - Changeset Plugin

The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue

PLUGIN Changeset

CVE-2021-24225

MEDIUM CVSS 5.4 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24209 - Changeset Plugin

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

PLUGIN Changeset

CVE-2021-24209

HIGH CVSS 7.2 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24210 - Changeset Plugin

There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another user one year ago (https://wordpress.org/support/topic/phast-php-used-for-remote-fetch/) that says that the php involved in the request only go to whitelisted pages but it's possible to redirect the victim to any domain.

PLUGIN Changeset

CVE-2021-24210

MEDIUM CVSS 6.1 2021-04-05
Threat Entry Updated 2025-03-24

CVE-2021-24177 - Changeset Plugin

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

PLUGIN Changeset

CVE-2021-24177

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24153 - Changeset Plugin

A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.

PLUGIN Changeset

CVE-2021-24153

MEDIUM CVSS 5.4 2021-04-05
Scroll to top