Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total7
Critical0
High2
Medium5
Reset
Showing 1-7 of 7 records
Threat Entry Updated 2026-04-15

CVE-2026-1277 - Url Shortify Plugin

The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via a crafted link.

PLUGIN Url Shortify

CVE-2026-1277

MEDIUM CVSS 4.7 2026-02-18
Threat Entry Updated 2025-12-15

CVE-2025-13355 - Url Shortify Plugin

The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Url Shortify

CVE-2025-13355

HIGH CVSS 7.1 2025-12-15
Threat Entry Updated 2025-12-15

CVE-2025-12684 - Url Shortify Plugin

The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected cross site scripting, which could be used against high-privilege users such as admins.

PLUGIN Url Shortify

CVE-2025-12684

HIGH CVSS 7.1 2025-12-15
Threat Entry Updated 2024-11-21

CVE-2023-5605 - Url Shortify Plugin

The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Url Shortify

CVE-2023-5605

MEDIUM CVSS 4.8 2023-11-06
Threat Entry Updated 2025-05-02

CVE-2023-4294 - Url Shortify Plugin

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

PLUGIN Url Shortify

CVE-2023-4294

MEDIUM CVSS 6.1 2023-09-11
Threat Entry Updated 2024-11-21

CVE-2023-3129 - Url Shortify Plugin

The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Url Shortify

CVE-2023-3129

MEDIUM CVSS 4.8 2023-07-10
Threat Entry Updated 2026-01-30

CVE-2021-24749 - Url Shortify Plugin

The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.

PLUGIN Url Shortify

CVE-2021-24749

MEDIUM CVSS 4.3 2021-11-29
Scroll to top