sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14
Critical1
High5
Medium8
Reset
Showing 1-14 of 14 records
Threat Entry Updated 2026-07-22

Wp Emember - Information Disclosure (CVE-2026-49077)

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.

PLUGIN Wp Emember

CVE-2026-49077

MEDIUM CVSS 5.3 2026-06-04
Threat Entry Updated 2026-06-17

Wp Emember - Cross-Site Scripting (XSS) (CVE-2024-5081)

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Wp Emember

CVE-2024-5081

MEDIUM CVSS 6.1 2024-08-05
Threat Entry Updated 2026-06-17

Wp Emember - Cross-Site Scripting (XSS) (CVE-2024-5715)

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Wp Emember

CVE-2024-5715

HIGH CVSS 7.1 2024-07-13
Threat Entry Updated 2026-06-17

Wp Emember - Cross-Site Scripting (XSS) (CVE-2024-5075)

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Wp Emember

CVE-2024-5075

MEDIUM CVSS 5.9 2024-07-13
Threat Entry Updated 2026-06-17

Wp Emember - Cross-Site Scripting (XSS) (CVE-2024-5074)

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Wp Emember

CVE-2024-5074

MEDIUM CVSS 5.4 2024-07-13