Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,213
Critical1,006
High3,355
Medium11,600
Reset
Showing 12641-12660 of 16213 records
Threat Entry Updated 2024-11-21

CVE-2023-5530 - Ninja Forms Contact Form Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts/comments etc however the vendor acknowledged and fixed the issue

PLUGIN Ninja Forms Contact Form

CVE-2023-5530

MEDIUM CVSS 4.8 2023-11-06
Threat Entry Updated 2025-03-24

CVE-2023-5355 - Awesome Support Plugin

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

PLUGIN Awesome Support

CVE-2023-5355

HIGH CVSS 8.1 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-5454 - Before 2 Plugin

The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.

PLUGIN Before 2

CVE-2023-5454

HIGH CVSS 7.5 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-5082 - History Log By Click5 Plugin

The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.

PLUGIN History Log By Click5

CVE-2023-5082

HIGH CVSS 7.2 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-4930 - Front End Pm Plugin

The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

PLUGIN Front End Pm

CVE-2023-4930

MEDIUM CVSS 6.5 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-5354 - Awesome Support Plugin

The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Awesome Support

CVE-2023-5354

MEDIUM CVSS 6.1 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-5228 - User Registration Plugin

The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN User Registration

CVE-2023-5228

MEDIUM CVSS 4.8 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-5181 - Wp Discord Invite Plugin

The WP Discord Invite WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Discord Invite

CVE-2023-5181

MEDIUM CVSS 4.8 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-5352 - Awesome Support Plugin

The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.

PLUGIN Awesome Support

CVE-2023-5352

MEDIUM CVSS 4.3 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-4858 - Simple Table Manager Plugin

The Simple Table Manager WordPress plugin through 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Simple Table Manager

CVE-2023-4858

MEDIUM CVSS 4.8 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-4810 - Responsive Pricing Table Plugin

The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Responsive Pricing Table

CVE-2023-4810

MEDIUM CVSS 4.8 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-46823 - Imagelinks Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.

PLUGIN Imagelinks

CVE-2023-46823

HIGH CVSS 7.2 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-45074 - Advanced Page Visit Counter Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.

PLUGIN Advanced Page Visit Counter

CVE-2023-45074

CRITICAL CVSS 9.8 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-45069 - Video Gallery Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.

PLUGIN Video Gallery

CVE-2023-45069

CRITICAL CVSS 9.8 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-35911 - Contact Form Generator Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.

PLUGIN Contact Form Generator

CVE-2023-35911

CRITICAL CVSS 9.8 2023-11-06
Threat Entry Updated 2025-02-19

CVE-2023-35910 - Quasar Form Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nucleus_genius Quasar form free – Contact Form Builder for WordPress allows SQL Injection.This issue affects Quasar form free – Contact Form Builder for WordPress: from n/a through 6.0.

PLUGIN Quasar Form

CVE-2023-35910

HIGH CVSS 8.8 2023-11-04
Threat Entry Updated 2025-02-19

CVE-2023-36529 - Houzez Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress Theme: from n/a through 1.3.4.

PLUGIN Houzez

CVE-2023-36529

CRITICAL CVSS 9.8 2023-11-03
Threat Entry Updated 2025-02-19

CVE-2023-32121 - Zero Spam For Wordpress Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zero Spam for WordPress allows SQL Injection.This issue affects Zero Spam for WordPress: from n/a through 5.4.4.

PLUGIN Zero Spam For Wordpress

CVE-2023-32121

HIGH CVSS 7.2 2023-11-03
Threat Entry Updated 2024-11-21

CVE-2023-5946 - Digirisk Plugin

The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter in version 6.0.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Digirisk

CVE-2023-5946

MEDIUM CVSS 6.1 2023-11-03
Threat Entry Updated 2025-02-19

CVE-2023-26015 - Mappress Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4.

PLUGIN Mappress

CVE-2023-26015

CRITICAL CVSS 9.8 2023-11-03
Scroll to top